A particularly serious cybersecurity case is once again bringing to the fore the dangers hidden behind seemingly “innocent” browser extensions. According to security researchers at OX Security, two deceptive Chrome extensions have compromised more than 900,000 users, secretly eavesdropping on conversations from ChatGPT and DeepSeek (as well as their entire browsing history).

When imitation becomes a threat
The malicious extensions almost perfectly mimicked the legitimate AI AITOPIA, an AI sidebar that allows quick access to large language models (LLMs) such as GPT and Claude. Most worryingly, one of the fake extensions even managed to receive a “Featured” badge from the Chrome Web Store, boosting its credibility in the eyes of users.
See also: New vulnerability in n8n allows arbitrary command execution
The OX Security team detected the threat during a routine malware pattern analysis, uncovering the two extensions that mimicked both the functionality and interface of AITOPIA.
The extensions that "trapped" hundreds of thousands of users
The two extensions in question appeared with the names:
- “Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI”, with over 600,000 users
- “AI Sidebar with Deepseek, ChatGPT, Claude and more”, with around 300,000 users
Both were asking for permission for “anonymous analytics,” a seemingly innocuous request that actually served as a cover for widespread data theft.

How data interception worked
Once installed, the extensions actively monitored browser tabs via the chrome.tabs.onUpdated. For each victim, they generated a unique identifier, called “gptChatId,” to associate data with specific users.
See also: Exploiting critical vulnerability in old D-Link DSL routers
When they detected that the user was visiting domains like chatgpt.com or deepseek.com, they started collecting data directly from the page's DOM: messages, responses, session IDs, and metadata. The data was stored locally, encoded in Base64, and then sent every 30 minutes to command-and-control (C2) servers like deepaichats.com and chatsaigpt.com.
What data was leaked and why this is critical
The eavesdropping was not limited to simple conversations. According to the researchers, the following were recorded:
- source code
- business strategies and plans
- personal information (PII)
- search queries
- internal company URLs
Unlike the legitimate AITOPIA, this data was not limited to the declared storage space, but was sent to third-party infrastructures, outside of any control.
Risks for businesses and individuals
Stolen conversations can reveal sensitive intellectual property, trade secrets or personal information that can be exploited for industrial espionage or sold on dark web marketplaces. At the same time, full browsing history allows attackers to map habits, organizational structures and roles within businesses, paving the way for targeted phishing attacks or identity theft.
See also: AdonisJS Bodyparser: Critical vulnerability allows writing files to the server
Hiding traces and deceptive practices
The perpetrators took care to hide their tracks by hosting privacy policies on platforms like Lovable.dev to obscure the true origin of the extensions. Furthermore, when users attempted to uninstall them, they were often redirected to other suspicious extensions, perpetuating the infection cycle.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What users should do
The incident is a stark warning. Experts recommend immediately checking installed extensions, removing those that are not absolutely necessary, and paying close attention to the permissions they request. In an era where AI tools are increasingly integrated into work and everyday life, data security is not just a technical issue – it is a matter of trust.
IoCs
| Type | Value | Notes |
|---|---|---|
| Extension name | Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI | Malicious AI sidebar-style extension |
| Extension ID | fnmihdojmnkclgjpcoonokmkhjpjechg | Chrome Web Store ID |
| Version | 1.9.6 | Reported malicious build |
| SHA-256 hash | 98d1f151872c27d0abae3887f7d6cb6e4ce29e99ad827cb077e1232bc4a69c00 | Package hash |
| Extension name | AI Sidebar with Deepseek, ChatGPT, Claude and more | Second malicious extension |
| Extension ID | inhcgfpbfdjbjogdfjbclgolkmhnooop | Chrome Web Store ID |
| Version | 1.6.1 | Reported malicious build |
| SHA-256 hash | 20ba72e91d7685926c8c1c5b4646616fa9d769e32c1bc4e9f15ddfad3429cea7 | Package hash |
Network and C2 IoCs
| Category | Domain / Endpoint | Notes |
|---|---|---|
| C2 endpoint | deepaichats[.]com | Receives stolen chat data and URLs |
| C2 endpoint | chatsaigpt[.]com | Additional C2 for exfiltrated data |
| Lovable-hosted server | chataigpt[.]pro | Used for privacy policy / infrastructure hosting |
| Lovable-hosted server | chatgptsidebar[.]pro | Used for uninstall redirect and infra |
