Drooid Logo
Back to story perspectives

Full Breakdown

Malicious Chrome Extensions Targeting AI Conversations

1/8/2026, 10:56:52 AM

Overview of the Malicious Extensions

Cybersecurity researchers have identified two malicious Chrome extensions, "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" and "AI Sidebar with Deepseek, ChatGPT, Claude, and more," which collectively have over 900,000 users. These extensions have been found to exfiltrate sensitive data, including conversations with AI chatbots like OpenAI's ChatGPT and DeepSeek, along with browsing data, to remote servers controlled by the attackers. The extensions were still available for download on the Chrome Web Store at the time of the report, although one had lost its "Featured" badge.

Mechanism of Data Exfiltration

The extensions operate by requesting user consent to collect "anonymous, non-identifiable analytics data." However, they instead harvest complete conversation content from ChatGPT and DeepSeek sessions, as well as URLs from all open browser tabs. This data is sent to remote command and control (C2) servers every 30 minutes. The malicious extensions utilize a legitimate AI-powered web development platform, Lovable, to obfuscate their activities and host their privacy policies.

Implications of Data Theft

The potential consequences of installing these extensions are significant. The data exfiltrated can be weaponized for various malicious purposes, including corporate espionage, identity theft, and targeted phishing campaigns. Organizations whose employees have installed these extensions may have inadvertently exposed sensitive information, including intellectual property and confidential business data.

Rising Trend of Prompt Poaching

This incident highlights a growing trend known as "prompt poaching," where malicious extensions and applications stealthily capture users' interactions with AI chatbots. Similar cases, such as the Urban VPN Proxy extension, have demonstrated that even highly rated extensions can engage in data harvesting. Researchers from OX Security have noted that the practice is becoming increasingly common, with more extensions appearing that exploit users' trust in reputable browser stores.

Official Statements & Responses

John Tuckner from Secure Annex stated, "It is clear prompt poaching has arrived to capture your most sensitive conversations and browser extensions are the exploit vector." He also raised concerns about whether these practices violate Google's policies regarding extension functionality. Users are advised to remove any suspicious extensions and avoid installing those from unknown sources, regardless of their ratings.

Criticism & Opposition

Critics have expressed concern over the implications of such malicious activities, particularly regarding user privacy and data security. The ease with which these extensions can infiltrate users' browsers raises questions about the effectiveness of current vetting processes for browser extensions in major stores.

What's Next

As the trend of prompt poaching continues to evolve, it is likely that more organizations will recognize the profitability of capturing user data through such means. Users are urged to remain vigilant and cautious when installing browser extensions, particularly those that request extensive permissions under the guise of enhancing user experience.