Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants
ID: 7c05ba90-7fce-59e2-afc0-9a699d0f2576
STIX ID: report--7c05ba90-7fce-59e2-afc0-9a699d0f2576
Feed Name: cybersecurityNews.com
A large campaign of counterfeit Chromium-based AI assistant extensions distributed via the Chrome Web Store amassed close to 900,000 installs and breached over 20,000 enterprise environments by harvesting ChatGPT and other AI chat histories, visited URLs, and browsing telemetry. The extensions mimicked legitimate tooling to evade vetting, logged data locally (Base64-encoded JSON), and exfiltrated staged data via scheduled HTTPS POSTs to attacker-controlled domains (e.g., deepaichats.com, chatsaigpt.com), while re-enabling collection after updates; organizations are advised to audit and allowlist extensions, monitor outbound POST traffic to known C2 domains, and enforce browser management and network protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
