Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Extensions Target AI Chat Platforms Users

Malicious Extensions Target AI Chat Platforms Users

Posted on June 5, 2026 By CWS

Users of AI platforms like ChatGPT, Claude, Copilot, Gemini, and DeepSeek are unknowingly exposing their personal and sensitive information. This vulnerability is being exploited by malicious browser extensions that are secretly collecting and transmitting data to unidentified servers.

Rising Threat of Malicious Extensions

The proliferation of AI-related browser extensions, which have reached approximately 115 million users globally as of March 2026, presents an attractive opportunity for cybercriminals. These extensions, posing as helpful tools, are covertly gathering user data, as revealed in a report by analysts at G Data and shared with Cyber Security News (CSN).

The report identifies three specific extensions: Urban VPN, Smart Sidebar, and AI Assistant (now Chat AI). These extensions, despite having high user ratings on the Chrome Web Store, are engaged in unauthorized data collection activities.

Data at Risk

These malicious extensions pose a significant threat due to the nature of the data being intercepted. Users often share personal information, confidential business data, and even medical records with AI platforms. This information, once intercepted, can be used for nefarious purposes such as fraud, blackmail, or corporate espionage.

The extensions operate by injecting scripts into the browser, intercepting network requests, and extracting conversation data without disrupting the AI platforms’ functionality. This makes detection by users extremely challenging.

Specific Extensions and Their Methods

Urban VPN, one of the most notorious extensions, was found to include a script that harvested data from multiple AI platforms, even when the VPN was inactive. Similarly, Smart Sidebar used a script to monitor and capture interactions on platforms like ChatGPT and DeepSeek, sending the data to suspicious domains.

The third extension, AI Assistant, incorporated a hidden iframe to intercept user interactions, forwarding data to unverified external URLs. Despite its ‘Featured’ status on the Chrome Web Store, it employed deceptive methods to gather information.

To protect against such threats, G Data advises users to only install extensions from trusted sources and apply the Principle of Least Privilege, ensuring extensions have minimal access permissions. Regular audits of installed extensions and organizational restrictions on browser access to sensitive platforms are also recommended.

Indicators of Compromise

The report highlights several indicators of compromise, including specific malicious extension hashes and detection names, which can aid in identifying and removing these harmful extensions.

For ongoing updates on cybersecurity threats, follow Cyber Security News on Google News, LinkedIn, and other platforms.

Cyber Security News Tags:AI security, browser extensions, ChatGPT, Chrome extensions, Claude, Copilot, Cybersecurity, data privacy, data protection, DeepSeek, digital privacy, Gemini, Malware, online safety

Post navigation

Previous Post: Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
Next Post: Microsoft 365 Resolves Driver Auto-Update Bypass Issue

Related Posts

Critical VMware XSS Vulnerabilities Exposed Critical VMware XSS Vulnerabilities Exposed Cyber Security News
Handala Hack Targets US, Israel with Destructive Cyberattacks Handala Hack Targets US, Israel with Destructive Cyberattacks Cyber Security News
EY Faces Data Breach: IT System Compromised EY Faces Data Breach: IT System Compromised Cyber Security News
ESPHome Web Server Authentication Bypass Vulnerability Exposes Smart Devices ESPHome Web Server Authentication Bypass Vulnerability Exposes Smart Devices Cyber Security News
Proxyware Malware Disguised as Notepad++ Tool Leverages Windows Explorer Process to Hijack Systems Proxyware Malware Disguised as Notepad++ Tool Leverages Windows Explorer Process to Hijack Systems Cyber Security News
MSBuild Exploited for Stealth Fileless Windows Attacks MSBuild Exploited for Stealth Fileless Windows Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes
  • Cisco Introduces Cost-Effective AI for Code Security
  • Accelerating Exploit Timelines Challenge Defenders
  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark