A Chrome extension, installed by around 100,000 users, is discreetly capturing inputs and responses across nine leading AI platforms. Despite its listing claiming no data collection, “Prompt Optimizer – SecondBrain” (ID: aajjgdpofhhcjmjoombjdfepplndhgcp, version 2.3.1) is actively recording interactions on platforms like ChatGPT, Claude, and Gemini.
Unveiling the Hidden Monitoring
Unlike traditional spyware, this extension activates without user input post-installation. Immediately upon loading, it modifies internal settings to assume user consent, enabling data collection and disabling protections. This operation raises significant privacy concerns as it continues to monitor user activity across all browser tabs.
The extension’s capture mechanism is embedded within a file deceptively named chatgpt_context_fetch_diagnostics.js. It overrides key browser functions to intercept network traffic, allowing it to operate across all nine AI platforms. This includes replacing functions like window.fetch and XMLHttpRequest, effectively capturing data before it reaches any AI service.
Security Risks in Corporate Environments
In corporate settings, the extension poses severe risks, particularly targeting Microsoft 365’s Copilot. By intercepting SignalR protocol frames, it extracts internal communications, creating potential data breaches. Organizations allowing this extension face the risk of sensitive information leaking outside their secure boundaries.
The data collected is encrypted and sent to ingest.secondbrain.is, but the encryption key is managed by SecondBrain, enabling them to decrypt all captured data. This capability has been confirmed through decrypted traffic analysis, revealing serious discrepancies between stated policies and actual data handling practices.
Enterprise Measures Against Data Breaches
To mitigate these risks, security teams should take immediate action. Blocking the extension by ID using Google Chrome and Microsoft Edge policies is crucial. Additionally, monitoring network logs for connections to SecondBrain’s servers can help identify unauthorized data transmissions.
For enterprises utilizing Microsoft 365 Copilot, treating this extension as a significant threat is essential. Rather than viewing it as a minor privacy concern, organizations should acknowledge its potential for extensive data exfiltration and adjust their security measures accordingly.
Overall, the discrepancy between SecondBrain’s privacy claims and its technical practices underlines the importance of rigorous security audits and proactive monitoring of browser extensions and network activities to protect sensitive data.
