started · updated
Chrome extension resurfaces to steal AI chatbot conversations
A malicious Google Chrome extension titled ‘AI Sidebar with DeepSeek, ChatGPT, Claude and more’ has resurfaced in the Chrome Web Store. Despite being previously removed in early 2026, the extension has returned, posing a significant security risk to users.
Cybersecurity researchers at Netskope Threat Labs identified a ‘clean and then poison’ strategy used by the developers. After releasing a seemingly legitimate version (1.7.2.0) to regain trust, the developers released version 1.7.3.0, which contained new code designed to steal user data. The extension was found to extract conversation text from AI chatbots like ChatGPT and DeepSeek, encoding the data in Base64 to transmit it to external domains without user knowledge.
Although the threat was reported to Google, the extension remains available on the Chrome Web Store at the time of reporting.
Entities
ChatGPT · Chrome · DeepSeek · Google · Netskope Threat Labs