Malicious Browser Extensions Hijack Users’ AI Chats in New “Prompt Poaching” Attack
ID: 13a39b2e-3072-5e9c-b8e6-0cc5054805ee
STIX ID: report--13a39b2e-3072-5e9c-b8e6-0cc5054805ee
Feed Name: GBHackers
Security researchers have identified a wave of malicious browser extensions—often clones or retrofitted legitimate tools—that monitor AI conversation tabs, capture user prompts and AI responses via API interception or DOM scraping, and exfiltrate the collected data to attacker-controlled servers (a practice termed “prompt poaching”), exposing PII and sensitive corporate information and prompting recommendations to restrict unapproved extensions, audit installed extensions, and prefer trusted vendors or standalone apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
