Malicious Browser Add-Ons Target Major AI Chatbot Users
ID: bbb6c95a-33f6-5d65-9e9d-3b8d2c804578
STIX ID: report--bbb6c95a-33f6-5d65-9e9d-3b8d2c804578
Feed Name: GBHackers
**Executive Summary:** Malicious Chrome extensions have been actively intercepting and exfiltrating user conversations and metadata from major AI platforms (ChatGPT, Claude, Copilot, Gemini, DeepSeek, etc.) by injecting JavaScript, observing DOM mutations or overriding fetch/XHR, encoding payloads (commonly Base64) and sending them to attacker-controlled endpoints; the report cites specific examples (Urban VPN, Smart Sidebar), outlines recurring TTPs and persistence techniques, and provides mitigation guidance for users and defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
