HomeSecurityChrome extensions have stolen conversations from ChatGPT and DeepSeek

Chrome extensions have stolen conversations from ChatGPT and DeepSeek

A particularly serious cybersecurity case is once again bringing to the fore the dangers hidden behind seemingly “innocent” browser extensions. According to security researchers at OX Security, two deceptive Chrome extensions have compromised more than 900,000 users, secretly eavesdropping on conversations from ChatGPT and DeepSeek (as well as their entire browsing history).

Chrome Extensions ChatGPT DeepSeek

When imitation becomes a threat

The malicious extensions almost perfectly mimicked the legitimate AI AITOPIA, an AI sidebar that allows quick access to large language models (LLMs) such as GPT and Claude. Most worryingly, one of the fake extensions even managed to receive a “Featured” badge from the Chrome Web Store, boosting its credibility in the eyes of users.

See also: New vulnerability in n8n allows arbitrary command execution

The OX Security team detected the threat during a routine malware pattern analysis, uncovering the two extensions that mimicked both the functionality and interface of AITOPIA.

The extensions that "trapped" hundreds of thousands of users

The two extensions in question appeared with the names:

  • “Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI”, with over 600,000 users
  • “AI Sidebar with Deepseek, ChatGPT, Claude and more”, with around 300,000 users

Both were asking for permission for “anonymous analytics,” a seemingly innocuous request that actually served as a cover for widespread data theft.

Chrome extensions have stolen conversations from ChatGPT and DeepSeek

How data interception worked

Once installed, the extensions actively monitored browser tabs via the chrome.tabs.onUpdated. For each victim, they generated a unique identifier, called “gptChatId,” to associate data with specific users.

See also: Exploiting critical vulnerability in old D-Link DSL routers

When they detected that the user was visiting domains like chatgpt.com or deepseek.com, they started collecting data directly from the page's DOM: messages, responses, session IDs, and metadata. The data was stored locally, encoded in Base64, and then sent every 30 minutes to command-and-control (C2) servers like deepaichats.com and chatsaigpt.com.

What data was leaked and why this is critical

The eavesdropping was not limited to simple conversations. According to the researchers, the following were recorded:

  • source code
  • business strategies and plans
  • personal information (PII)
  • search queries
  • internal company URLs

Unlike the legitimate AITOPIA, this data was not limited to the declared storage space, but was sent to third-party infrastructures, outside of any control.

Risks for businesses and individuals

Stolen conversations can reveal sensitive intellectual property, trade secrets or personal information that can be exploited for industrial espionage or sold on dark web marketplaces. At the same time, full browsing history allows attackers to map habits, organizational structures and roles within businesses, paving the way for targeted phishing attacks or identity theft.

See also: AdonisJS Bodyparser: Critical vulnerability allows writing files to the server

Hiding traces and deceptive practices

The perpetrators took care to hide their tracks by hosting privacy policies on platforms like Lovable.dev to obscure the true origin of the extensions. Furthermore, when users attempted to uninstall them, they were often redirected to other suspicious extensions, perpetuating the infection cycle.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Chrome extensions have stolen conversations from ChatGPT and DeepSeek

What users should do

The incident is a stark warning. Experts recommend immediately checking installed extensions, removing those that are not absolutely necessary, and paying close attention to the permissions they request. In an era where AI tools are increasingly integrated into work and everyday life, data security is not just a technical issue – it is a matter of trust.

IoCs

TypeValueNotes
Extension nameChat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AIMalicious AI sidebar-style extension
Extension IDfnmihdojmnkclgjpcoonokmkhjpjechgChrome Web Store ID
Version1.9.6Reported malicious build
SHA-256 hash98d1f151872c27d0abae3887f7d6cb6e4ce29e99ad827cb077e1232bc4a69c00Package hash
Extension nameAI Sidebar with Deepseek, ChatGPT, Claude and moreSecond malicious extension
Extension IDinhcgfpbfdjbjogdfjbclgolkmhnooopChrome Web Store ID
Version1.6.1Reported malicious build
SHA-256 hash20ba72e91d7685926c8c1c5b4646616fa9d769e32c1bc4e9f15ddfad3429cea7Package hash

Network and C2 IoCs

CategoryDomain / EndpointNotes
C2 endpointdeepaichats[.]comReceives stolen chat data and URLs
C2 endpointchatsaigpt[.]comAdditional C2 for exfiltrated data
Lovable-hosted serverchataigpt[.]proUsed for privacy policy / infrastructure hosting
Lovable-hosted serverchatgptsidebar[.]proUsed for uninstall redirect and infra
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS