Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 2 sources · 13 days · First seen · Last updated
Malicious Chrome extensions targeting AI conversations
Overview
Security researchers have identified malicious Google Chrome extensions designed to intercept and steal user conversations from various AI platforms, including ChatGPT, Claude, Gemini, and DeepSeek.
Initial reports highlighted an extension named ‘Prompt Optimizer – SecondBrain’ (version 2.3.1) installed on approximately 100,000 devices. This extension reportedly bypassed privacy claims by using the Fetch API, XMLHttpRequest, and WebSocket to record full user conversations. The collected data was encrypted with AES-GCM using a server-supplied key for later decryption.
Subsequent findings revealed that a similar threat, titled ‘AI Sidebar with DeepSeek, ChatGPT, Claude and more’, resurfaced in the Chrome Web Store despite being previously removed. Researchers identified a ‘clean and then poison’ strategy, where developers released a legitimate version to regain trust before deploying a version containing malicious code. This version encoded conversation text in Base64 to transmit it to external domains without user knowledge.
Entities
ChatGPT · Google · DeepSeek · Chrome · AES‑GCM encryption
Timeline
-
about 1 month ago
[TECHNOLOGY] 2 sourcesChrome extension resurfaces to steal AI chatbot conversationsA malicious Chrome extension masquerading as an AI assistant has resurfaced, stealing ChatGPT and DeepSeek conversations by sending data to external servers.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesGoogle Chrome's RAM drain and hidden extension spy raise user concernsGoogle Chrome's high RAM usage and a malicious extension that records AI chats on 100,000 devices highlight performance and privacy risks for users.
Sources
4gnews.pt · seucreditodigital.com.br