An extension previously removed from the Chrome Web Store due to allegations of conversation theft is once again available, posing potential threats to enterprise systems. Netskope Threat Labs reports that this extension, involved in malicious activities, is being redistributed through Google’s CRX infrastructure.
Return of the Suspicious Extension
The extension, known as ‘AI Sidebar with DeepSeek, ChatGPT, Claude and more,’ was initially flagged for scraping AI conversation content and routing it to external domains. OX Security had identified these activities in December 2025, leading to its removal despite having over 300,000 installs and a high rating.
Although its problematic features were removed in later versions, the extension has resurfaced in August 2026. Netskope indicates that it now carries a different type of payload, suggesting renewed risks for users.
Current Activities and Distribution
The latest builds, particularly version 1.7.2.0 and 1.7.3.0, reveal a strategic shift. While version 1.7.2.0 appeared clean to build trust, version 1.7.3.0 introduced a newly devised scheme that monetizes update and uninstall events through affiliate links.
This scheme uses a Chrome quirk to ensure that even when users uninstall the extension, they inadvertently generate referral commissions. Such tactics raise concerns about the potential for more harmful payloads in the future.
Security Concerns and Recommendations
Netskope has flagged the extension as Trojan.GenericFCA.Script.37952 and blocked its distribution via Google’s CDN. The operation appears linked to Extchange.com, lacking public registrant details, and falsely claims DeepSeek AI as the developer.
The firm warns organizations to uninstall the extension and remain vigilant, as the channel could potentially distribute more malicious software. The affiliate scheme itself is considered low risk, but the threat of a more severe payload persists.
In light of these developments, security experts advise constant monitoring and quick action to mitigate potential threats from such extensions.
