Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats

Impersonating a legitimate extension from AITOPIA, the two malicious extensions were also exfiltrating users’ browser activity.

Chrome security

Two malicious Chrome extensions were observed exfiltrating browser data and users’ conversations with ChatGPT and DeepSeek, OX Security reports.

Impersonating a legitimate extension from AITOPIA, the two extensions gathered over 900,000 downloads, potentially impacting as many users.

The applications, called ‘Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI’ and ‘AI Sidebar with Deepseek, ChatGPT, Claude and more’, are no longer available in the Chrome web store.

According to OX Security, the extensions were abusing the AI-powered web development platform Lovable to host infrastructure components and anonymize their activity.

The legitimate AITOPIA extension they were impersonating allows users to chat with popular LLM models through a sidebar on top of visited websites.

The malicious applications copied the legitimate extension and added code that requested user consent to harvest “anonymous, non-identifiable analytics data” but instead stole the users’ complete ChatGPT and DeepSeek conversations.

Advertisement. Scroll to continue reading.

Both extensions, OX Security says, collected all URLs from Chrome tabs, search queries, URL parameters containing session tokens, user IDs, and other authentication data.

By stealing the URLs from all browser tabs, they potentially leaked internal corporate domains, likely exposing corporate infrastructure and tools, OX Security says.

Depending on how the affected users interacted with the LLM models, the extensions potentially exfiltrated source code and development queries, personally identifiable information (PII), sensitive information such as confidential data and legal matters, and business strategies and planning.

“This data can be weaponized for corporate espionage, identity theft, targeted phishing campaigns, or sold on underground forums. Organizations whose employees installed these extensions may have unknowingly exposed intellectual property, customer data, and confidential business information,” OX Security notes.

Users are advised to remove the malicious extensions from their Chrome browser as soon as possible.

Related: GhostPoster Firefox Extensions Hide Malware in Icons

Related: Chrome, Edge Extensions Caught Tracking Users, Creating Backdoors

Related: Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks

Related: New Firefox Extensions Required to Disclose Data Collection Practices

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.