Malicious AI Assistant Extensions Harvest LLM Chat Histories
ID: 1534058e-d5c6-5bfb-b0b6-6237a2bf49a8
STIX ID: report--1534058e-d5c6-5bfb-b0b6-6237a2bf49a8
Feed Name: Microsoft Security
Date Published: 2026-03-05
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
Microsoft Defender identified a large-scale campaign of malicious Chromium browser extensions masquerading as AI assistant tools that collect full URLs, AI chat content (e.g., ChatGPT and DeepSeek), and browsing telemetry. The extensions were distributed through the Chrome Web Store (affecting Chrome and Edge), reached ~900,000 installs and impacted >20,000 enterprise tenants, staged data locally (Base64 JSON) and periodically exfiltrated it via HTTPS POST to domains such as deepaichats.com and chatsaigpt.com, with telemetry re-enabled after updates; Microsoft recommends monitoring network POSTs to known endpoints, auditing and restricting extensions, enabling Defender protections, applying AI data security controls, and educating users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
