logo

Malicious Browser Extensions Hijack Users’ AI Chats in New “Prompt Poaching” Attack

ID: 13a39b2e-3072-5e9c-b8e6-0cc5054805ee

STIX ID: report--13a39b2e-3072-5e9c-b8e6-0cc5054805ee

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-28

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Security researchers have identified a wave of malicious browser extensions—often clones or retrofitted legitimate tools—that monitor AI conversation tabs, capture user prompts and AI responses via API interception or DOM scraping, and exfiltrate the collected data to attacker-controlled servers (a practice termed “prompt poaching”), exposing PII and sensitive corporate information and prompting recommendations to restrict unapproved extensions, audit installed extensions, and prefer trusted vendors or standalone apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.