logo

On the radar: ChatGPT Stealer

ID: 5efc2c00-5278-59fd-a0dc-7c2b48d7952f

STIX ID: report--5efc2c00-5278-59fd-a0dc-7c2b48d7952f

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-27

...
...

Malicious browser extensions are performing "prompt poaching": monitoring open tabs for AI chat clients, scraping or intercepting question/answer content, and exfiltrating those conversations to attacker-controlled servers. The report includes examples (extension names and IDs), notes that actors clone or modify popular extensions to add this functionality, outlines risks (identity theft, targeted phishing, IP exposure), and recommends restricting unapproved extensions, reviewing permissions, and centrally managing browser extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.