Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Extensions Target AI Chat Platforms Users

Malicious Extensions Target AI Chat Platforms Users

Posted on June 5, 2026 By CWS

Users of AI platforms like ChatGPT, Claude, Copilot, Gemini, and DeepSeek are unknowingly exposing their personal and sensitive information. This vulnerability is being exploited by malicious browser extensions that are secretly collecting and transmitting data to unidentified servers.

Rising Threat of Malicious Extensions

The proliferation of AI-related browser extensions, which have reached approximately 115 million users globally as of March 2026, presents an attractive opportunity for cybercriminals. These extensions, posing as helpful tools, are covertly gathering user data, as revealed in a report by analysts at G Data and shared with Cyber Security News (CSN).

The report identifies three specific extensions: Urban VPN, Smart Sidebar, and AI Assistant (now Chat AI). These extensions, despite having high user ratings on the Chrome Web Store, are engaged in unauthorized data collection activities.

Data at Risk

These malicious extensions pose a significant threat due to the nature of the data being intercepted. Users often share personal information, confidential business data, and even medical records with AI platforms. This information, once intercepted, can be used for nefarious purposes such as fraud, blackmail, or corporate espionage.

The extensions operate by injecting scripts into the browser, intercepting network requests, and extracting conversation data without disrupting the AI platforms’ functionality. This makes detection by users extremely challenging.

Specific Extensions and Their Methods

Urban VPN, one of the most notorious extensions, was found to include a script that harvested data from multiple AI platforms, even when the VPN was inactive. Similarly, Smart Sidebar used a script to monitor and capture interactions on platforms like ChatGPT and DeepSeek, sending the data to suspicious domains.

The third extension, AI Assistant, incorporated a hidden iframe to intercept user interactions, forwarding data to unverified external URLs. Despite its ‘Featured’ status on the Chrome Web Store, it employed deceptive methods to gather information.

To protect against such threats, G Data advises users to only install extensions from trusted sources and apply the Principle of Least Privilege, ensuring extensions have minimal access permissions. Regular audits of installed extensions and organizational restrictions on browser access to sensitive platforms are also recommended.

Indicators of Compromise

The report highlights several indicators of compromise, including specific malicious extension hashes and detection names, which can aid in identifying and removing these harmful extensions.

For ongoing updates on cybersecurity threats, follow Cyber Security News on Google News, LinkedIn, and other platforms.

Cyber Security News Tags:AI security, browser extensions, ChatGPT, Chrome extensions, Claude, Copilot, Cybersecurity, data privacy, data protection, DeepSeek, digital privacy, Gemini, Malware, online safety

Post navigation

Previous Post: Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
Next Post: Microsoft 365 Resolves Driver Auto-Update Bypass Issue

Related Posts

Hackers Exploiting Adobe Magento RCE Vulnerability Exploited in the Wild Hackers Exploiting Adobe Magento RCE Vulnerability Exploited in the Wild Cyber Security News
Phishing Attacks Exploit RCS and iMessage to Evade Security Phishing Attacks Exploit RCS and iMessage to Evade Security Cyber Security News
New Unauthenticated DoS Vulnerability Crashes Next.js Servers with a Single Request New Unauthenticated DoS Vulnerability Crashes Next.js Servers with a Single Request Cyber Security News
New Eleven11bot Hacked 86,000 IP Cameras for Massive DDoS Attack New Eleven11bot Hacked 86,000 IP Cameras for Massive DDoS Attack Cyber Security News
Google Enhances Security, Blocks 1.75 Million Malicious Apps Google Enhances Security, Blocks 1.75 Million Malicious Apps Cyber Security News
Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
  • Chrome 149 Update Fixes Record 429 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark