< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 2 sources · 13 days · First seen · Last updated

Malicious Chrome extensions targeting AI conversations

Overview

Security researchers have identified malicious Google Chrome extensions designed to intercept and steal user conversations from various AI platforms, including ChatGPT, Claude, Gemini, and DeepSeek.

Initial reports highlighted an extension named ‘Prompt Optimizer – SecondBrain’ (version 2.3.1) installed on approximately 100,000 devices. This extension reportedly bypassed privacy claims by using the Fetch API, XMLHttpRequest, and WebSocket to record full user conversations. The collected data was encrypted with AES-GCM using a server-supplied key for later decryption.

Subsequent findings revealed that a similar threat, titled ‘AI Sidebar with DeepSeek, ChatGPT, Claude and more’, resurfaced in the Chrome Web Store despite being previously removed. Researchers identified a ‘clean and then poison’ strategy, where developers released a legitimate version to regain trust before deploying a version containing malicious code. This version encoded conversation text in Base64 to transmit it to external domains without user knowledge.

Entities

ChatGPT · Google · DeepSeek · Chrome · AES‑GCM encryption

Timeline

  1. about 1 month ago

    [TECHNOLOGY] 2 sources
    Chrome extension resurfaces to steal AI chatbot conversations

    A malicious Chrome extension masquerading as an AI assistant has resurfaced, stealing ChatGPT and DeepSeek conversations by sending data to external servers.

  2. about 1 month ago

    [TECHNOLOGY] 2 sources
    Google Chrome's RAM drain and hidden extension spy raise user concerns

    Google Chrome's high RAM usage and a malicious extension that records AI chats on 100,000 devices highlight performance and privacy risks for users.

Sources

4gnews.pt · seucreditodigital.com.br