900,000 Users Hit as Malicious Chrome Extensions Steal ChatGPT, DeepSeek Chats
ID: 885179d7-0d78-588b-8b6e-d54fe78c5620
STIX ID: report--885179d7-0d78-588b-8b6e-d54fe78c5620
Feed Name: TechRepublic Security
**Executive summary:** OX Security reported that malicious Chrome extensions masquerading as productivity tools exposed sensitive ChatGPT and DeepSeek conversations from over 900,000 users by abusing extension permissions and browser APIs to scrape DOM content, tag sessions with unique identifiers, aggregate and Base64-encode data, and periodically exfiltrate it to attacker-controlled C2 servers; the article describes the technical TTPs and recommends removal, allowlisting, DLP, monitoring, and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
