Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats

Posted on January 7, 2026January 7, 2026 By CWS

Two malicious Chrome extensions had been noticed exfiltrating browser knowledge and customers’ conversations with ChatGPT and DeepSeek, OX Safety experiences.

Impersonating a legit extension from AITOPIA, the 2 extensions gathered over 900,000 downloads, probably impacting as many customers.

The functions, known as ‘Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI’ and ‘AI Sidebar with Deepseek, ChatGPT, Claude and extra’, are not obtainable within the Chrome net retailer.

In response to OX Safety, the extensions had been abusing the AI-powered net growth platform Lovable to host infrastructure elements and anonymize their exercise.

The legit AITOPIA extension they had been impersonating permits customers to speak with fashionable LLM fashions by a sidebar on prime of visited web sites.

The malicious functions copied the legit extension and added code that requested consumer consent to reap “nameless, non-identifiable analytics knowledge” however as a substitute stole the customers’ full ChatGPT and DeepSeek conversations.Commercial. Scroll to proceed studying.

Each extensions, OX Safety says, collected all URLs from Chrome tabs, search queries, URL parameters containing session tokens, consumer IDs, and different authentication knowledge.

By stealing the URLs from all browser tabs, they probably leaked inner company domains, seemingly exposing company infrastructure and instruments, OX Safety says.

Relying on how the affected customers interacted with the LLM fashions, the extensions probably exfiltrated supply code and growth queries, personally identifiable data (PII), delicate data reminiscent of confidential knowledge and authorized issues, and enterprise methods and planning.

“This knowledge might be weaponized for company espionage, id theft, focused phishing campaigns, or bought on underground boards. Organizations whose workers put in these extensions might have unknowingly uncovered mental property, buyer knowledge, and confidential enterprise data,” OX Safety notes.

Customers are suggested to take away the malicious extensions from their Chrome browser as quickly as attainable.

Associated: GhostPoster Firefox Extensions Cover Malware in Icons

Associated: Chrome, Edge Extensions Caught Monitoring Customers, Creating Backdoors

Associated: Google Fortifies Chrome Agentic AI In opposition to Oblique Immediate Injection Assaults

Associated: New Firefox Extensions Required to Disclose Knowledge Assortment Practices

Security Week News Tags:Caught, Chats, Chrome, Downloads, Extensions, Stealing

Post navigation

Previous Post: GoBruteforcer Botnet Attacking Linux Servers Worldwide
Next Post: The Loudest Voices in Security Often Have the Least to Lose

Related Posts

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature Security Week News
Critical Vulnerability Exposes Many Mitel MiCollab Instances to Remote Hacking Security Week News
Hackers Steal Sensitive Data From Auction House Sotheby’s Security Week News
Vulnerabilities in CISA KEV Are Not Equally Critical: Report Security Week News
Email Security Startup AegisAI Launches With $13 Million in Funding Security Week News
Sesame Workshop Regains Control of Elmo’s Hacked X Account After Racist Posts Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • What tools help reduce fraud or friendly fraud for online businesses? 
  • WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
  • UK Government Unveils New Cyber Action Plan
  • UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia
  • ChatGPT Health – A Dedicated Space for Health Queries With Strong Privacy and Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • What tools help reduce fraud or friendly fraud for online businesses? 
  • WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
  • UK Government Unveils New Cyber Action Plan
  • UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia
  • ChatGPT Health – A Dedicated Space for Health Queries With Strong Privacy and Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark