3 Sources
[1]
Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users
Cybersecurity researchers have discovered two new malicious extensions on the Chrome Web Store that are designed to exfiltrate OpenAI ChatGPT and DeepSeek conversations alongside browsing data to servers under the attackers' control. The names of the extensions, which collectively have over
[2]
This new malware campaign is stealing chat logs via Chrome extensions
Similar cases (e.g., Urban VPN Proxy) show even highly rated extensions on official stores can harvest chats, credentials, and payment data A new malicious practice has emerged called "Prompt poaching" - where extensions, add-ons, and other apps, eavesdrop on people's conversations with AI
[3]
These Popular Chrome Extensions Are Stealing Your AI Chats
Just because a browser extension is labeled as featured or verified doesn't mean it can be trusted. Hackers continue to find ways to sneak malicious extensions into the Chrome web store -- this time, the two offenders are impersonating an add-on that allows users to have conversations with ChatGPT
Share
Copy Link
Cybersecurity researchers uncovered two malicious Chrome extensions that exfiltrated ChatGPT and DeepSeek conversations from over 900,000 users. The extensions disguised themselves as legitimate AI tools while secretly harvesting AI chatbot conversations and browsing data every 30 minutes. This attack method, dubbed Prompt Poaching, raises concerns about user privacy and corporate espionage as even featured extensions on official stores prove vulnerable.
Cybersecurity researchers at OX Security have identified two malicious Chrome extensions collectively installed by more than 900,000 users that were designed to steal AI chats and browsing data
1
. The extensions, named "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" and "AI Sidebar with Deepseek, ChatGPT, Claude, and more," impersonate a legitimate extension from AITOPIA that has approximately 1 million users2
. The first extension had garnered over 600,000 users and carried a Featured badge, while the second appeared verified with 300,000 users3
.
Source: Lifehacker
According to OX Security researcher Moshe Siman Tov Bustan, the extensions "were found exfiltrating user conversations and all Chrome tab URLs to a remote C2 server every 30 minutes"
1
. The malware operates by requesting consent for "anonymous, non-identifiable analytics data" to supposedly improve the sidebar experience, while actually stealing user conversations from ChatGPT and DeepSeek sessions2
. Once users grant permission, the rogue extensions begin harvesting information by searching for specific DOM elements inside web pages, extracting chat messages, and storing them locally before transmitting to remote servers at "chatsaigpt[.]com" or "deepaichats[.]com"1
. Threat actors leveraged Lovable, an AI-powered web development platform, to host their privacy policies and infrastructure components in an attempt to obfuscate their actions3
.
Source: Hacker News
This tactic of using browser extensions to stealthily capture AI conversations has been codenamed Prompt Poaching by Secure Annex
1
. The practice follows similar discoveries, including Urban VPN Proxy—an extension with millions of installations on Google Chrome and Microsoft Edge that was caught spying on users' AI chatbot conversations2
. Secure Annex also identified legitimate browser extensions such as Similarweb and Sensor Tower's Stayfocusd, with 1 million and 600,000 users respectively, engaging in stealing chat logs1
. Similarweb introduced the ability to monitor AI chatbot conversations in May 2025, with a January 1, 2026 update adding a terms of service pop-up explicitly stating that data entered into AI tools is collected1
.Related Stories
The consequences of installing such malicious Chrome extensions can be severe for both individuals and organizations. The stolen data includes sensitive information shared with chatbots like ChatGPT and DeepSeek, web browsing activity, search queries, internal corporate URLs, session tokens, user IDs, and authentication data
3
. "This data can be weaponized for corporate espionage, identity theft, targeted phishing campaigns, or sold on underground forums," OX Security warned1
. Organizations whose employees installed these extensions may have unknowingly exposed intellectual property, customer data, and confidential business information to threat actors1
. Researchers also discovered that if users uninstalled one extension, the other would open in a new tab attempting to trick users into installing the alternative3
.What makes Prompt Poaching particularly worrisome is that most of these extensions were found on the Chrome Web Store, with some even earning Featured and Verified badges
2
. As of the initial reporting, the extensions were still available for download, though "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" had been stripped of its Featured badge1
. Users should navigate to chrome://extensions/ to check for and remove the malicious impersonators3
. Security experts emphasize that ratings and reviews cannot be blindly trusted, as some threat actors convert legitimate extensions to malware years after launch. Users should vet extensions carefully for red flags, research developers on platforms like Google and Reddit, and regularly audit installed extensions to minimize risk to user privacy3
. The emergence of Prompt Poaching targeting popular AI services like Claude and Gemini signals that threat actors are adapting their tactics to exploit the growing reliance on AI chatbot conversations for both personal and professional use.Summarized by
Navi
17 Dec 2025•Technology

12 Feb 2026•Technology

26 Jan 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
