Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats

Posted on January 7, 2026January 7, 2026 By CWS

Two malicious Chrome extensions had been noticed exfiltrating browser knowledge and customers’ conversations with ChatGPT and DeepSeek, OX Safety experiences.

Impersonating a legit extension from AITOPIA, the 2 extensions gathered over 900,000 downloads, probably impacting as many customers.

The functions, known as ‘Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI’ and ‘AI Sidebar with Deepseek, ChatGPT, Claude and extra’, are not obtainable within the Chrome net retailer.

In response to OX Safety, the extensions had been abusing the AI-powered net growth platform Lovable to host infrastructure elements and anonymize their exercise.

The legit AITOPIA extension they had been impersonating permits customers to speak with fashionable LLM fashions by a sidebar on prime of visited web sites.

The malicious functions copied the legit extension and added code that requested consumer consent to reap “nameless, non-identifiable analytics knowledge” however as a substitute stole the customers’ full ChatGPT and DeepSeek conversations.Commercial. Scroll to proceed studying.

Each extensions, OX Safety says, collected all URLs from Chrome tabs, search queries, URL parameters containing session tokens, consumer IDs, and different authentication knowledge.

By stealing the URLs from all browser tabs, they probably leaked inner company domains, seemingly exposing company infrastructure and instruments, OX Safety says.

Relying on how the affected customers interacted with the LLM fashions, the extensions probably exfiltrated supply code and growth queries, personally identifiable data (PII), delicate data reminiscent of confidential knowledge and authorized issues, and enterprise methods and planning.

“This knowledge might be weaponized for company espionage, id theft, focused phishing campaigns, or bought on underground boards. Organizations whose workers put in these extensions might have unknowingly uncovered mental property, buyer knowledge, and confidential enterprise data,” OX Safety notes.

Customers are suggested to take away the malicious extensions from their Chrome browser as quickly as attainable.

Associated: GhostPoster Firefox Extensions Cover Malware in Icons

Associated: Chrome, Edge Extensions Caught Monitoring Customers, Creating Backdoors

Associated: Google Fortifies Chrome Agentic AI In opposition to Oblique Immediate Injection Assaults

Associated: New Firefox Extensions Required to Disclose Knowledge Assortment Practices

Security Week News Tags:Caught, Chats, Chrome, Downloads, Extensions, Stealing

Post navigation

Previous Post: GoBruteforcer Botnet Attacking Linux Servers Worldwide
Next Post: The Loudest Voices in Security Often Have the Least to Lose

Related Posts

Cybersecurity M&A Roundup: 40 Deals Announced in September 2025 Security Week News
Soverli Raises $2.6 Million for Secure Smartphone OS Security Week News
Gabbard Says UK Scraps Demand for Apple to Give Backdoor Access to Data Security Week News
40,000 Security Cameras Exposed to Remote Hacking Security Week News
Data Breach at Doctors Imaging Group Impacts 171,000 People Security Week News
100,000 Impacted by Cornwell Quality Tools Data Breach  Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment
  • Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
  • Tim Kosiba Named NSA Deputy Director
  • Cyber Threats Targeting Australia and New Zealand Fueled by Initial Access Sales, and Ransomware Campaigns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment
  • Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
  • Tim Kosiba Named NSA Deputy Director
  • Cyber Threats Targeting Australia and New Zealand Fueled by Initial Access Sales, and Ransomware Campaigns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark