logo

Malicious Browser Add-Ons Target Major AI Chatbot Users

ID: bbb6c95a-33f6-5d65-9e9d-3b8d2c804578

STIX ID: report--bbb6c95a-33f6-5d65-9e9d-3b8d2c804578

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Mayura Kathir

...
...

**Executive Summary:** Malicious Chrome extensions have been actively intercepting and exfiltrating user conversations and metadata from major AI platforms (ChatGPT, Claude, Copilot, Gemini, DeepSeek, etc.) by injecting JavaScript, observing DOM mutations or overriding fetch/XHR, encoding payloads (commonly Base64) and sending them to attacker-controlled endpoints; the report cites specific examples (Urban VPN, Smart Sidebar), outlines recurring TTPs and persistence techniques, and provides mitigation guidance for users and defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.