logo

900,000 Users Hit as Malicious Chrome Extensions Steal ChatGPT, DeepSeek Chats

ID: 885179d7-0d78-588b-8b6e-d54fe78c5620

STIX ID: report--885179d7-0d78-588b-8b6e-d54fe78c5620

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

**Executive summary:** OX Security reported that malicious Chrome extensions masquerading as productivity tools exposed sensitive ChatGPT and DeepSeek conversations from over 900,000 users by abusing extension permissions and browser APIs to scrape DOM content, tag sessions with unique identifiers, aggregate and Base64-encode data, and periodically exfiltrate it to attacker-controlled C2 servers; the article describes the technical TTPs and recommends removal, allowlisting, DLP, monitoring, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.