Chrome Extensions Caught Exfiltrating ChatGPT and DeepSeek Conversations from Over 900,000 Users
ID: 555e7f7e-4cc6-5615-a251-b384d64ed30c
STIX ID: report--555e7f7e-4cc6-5615-a251-b384d64ed30c
Feed Name: CyberNexora News
Executive Summary: Researchers discovered two malicious Chrome extensions marketed as AI productivity tools that collected user prompts, AI-generated responses, open-tab URLs, and browser metadata from platforms like ChatGPT and DeepSeek; with over 900,000 installs, the extensions used DOM parsing, permissions abuse, local storage, and periodic exfiltration to send sensitive data to attacker-controlled servers, creating significant risk of corporate espionage, identity theft, targeted phishing, and sale of confidential information.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
