Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Extensions Target AI Chat Platforms Users

Malicious Extensions Target AI Chat Platforms Users

Posted on June 5, 2026 By CWS

Users of AI platforms like ChatGPT, Claude, Copilot, Gemini, and DeepSeek are unknowingly exposing their personal and sensitive information. This vulnerability is being exploited by malicious browser extensions that are secretly collecting and transmitting data to unidentified servers.

Rising Threat of Malicious Extensions

The proliferation of AI-related browser extensions, which have reached approximately 115 million users globally as of March 2026, presents an attractive opportunity for cybercriminals. These extensions, posing as helpful tools, are covertly gathering user data, as revealed in a report by analysts at G Data and shared with Cyber Security News (CSN).

The report identifies three specific extensions: Urban VPN, Smart Sidebar, and AI Assistant (now Chat AI). These extensions, despite having high user ratings on the Chrome Web Store, are engaged in unauthorized data collection activities.

Data at Risk

These malicious extensions pose a significant threat due to the nature of the data being intercepted. Users often share personal information, confidential business data, and even medical records with AI platforms. This information, once intercepted, can be used for nefarious purposes such as fraud, blackmail, or corporate espionage.

The extensions operate by injecting scripts into the browser, intercepting network requests, and extracting conversation data without disrupting the AI platforms’ functionality. This makes detection by users extremely challenging.

Specific Extensions and Their Methods

Urban VPN, one of the most notorious extensions, was found to include a script that harvested data from multiple AI platforms, even when the VPN was inactive. Similarly, Smart Sidebar used a script to monitor and capture interactions on platforms like ChatGPT and DeepSeek, sending the data to suspicious domains.

The third extension, AI Assistant, incorporated a hidden iframe to intercept user interactions, forwarding data to unverified external URLs. Despite its ‘Featured’ status on the Chrome Web Store, it employed deceptive methods to gather information.

To protect against such threats, G Data advises users to only install extensions from trusted sources and apply the Principle of Least Privilege, ensuring extensions have minimal access permissions. Regular audits of installed extensions and organizational restrictions on browser access to sensitive platforms are also recommended.

Indicators of Compromise

The report highlights several indicators of compromise, including specific malicious extension hashes and detection names, which can aid in identifying and removing these harmful extensions.

For ongoing updates on cybersecurity threats, follow Cyber Security News on Google News, LinkedIn, and other platforms.

Cyber Security News Tags:AI security, browser extensions, ChatGPT, Chrome extensions, Claude, Copilot, Cybersecurity, data privacy, data protection, DeepSeek, digital privacy, Gemini, Malware, online safety

Post navigation

Previous Post: Reaper Malware Threatens Mac Users with Browser and Wallet Attacks
Next Post: Microsoft 365 Resolves Driver Auto-Update Bypass Issue

Related Posts

Security Researchers Expose Lazarus Recruitment Pipeline Live on Camera Through Honeypot Operation Security Researchers Expose Lazarus Recruitment Pipeline Live on Camera Through Honeypot Operation Cyber Security News
How Businesses Prevent Credential Theft with Early Phishing Detection How Businesses Prevent Credential Theft with Early Phishing Detection Cyber Security News
CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks Cyber Security News
Google Awards M Through Bug Bounty Program in 2025 Google Awards $17M Through Bug Bounty Program in 2025 Cyber Security News
Microsoft Teams Issue Blocks Users From Opening Embedded Office Documents Microsoft Teams Issue Blocks Users From Opening Embedded Office Documents Cyber Security News
Microsoft to End OneDrive Sync Support for Windows 10 Microsoft to End OneDrive Sync Support for Windows 10 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zimbra Releases Critical Security Patches for Vulnerabilities
  • AWS Kiro Vulnerability Exposed Code Execution Risk
  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zimbra Releases Critical Security Patches for Vulnerabilities
  • AWS Kiro Vulnerability Exposed Code Execution Risk
  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark