The introduction of ads in the free version of ChatGPT appears to have opened up new avenues for cybercriminals, who are quick to exploit the change to scam unsuspecting users. Researchers have identified a malicious Google Chrome extension called “ChatGPT Ad Blocker,” which is presented as an ad-blocking tool, but in reality functions as mechanism chat-eavesdropping.

This development highlights a new wave of threats that directly target artificial intelligence users, with attackers exploiting the public's trust in tools that promise an improved user experience.
See also: SparkCat malware: New variant steals crypto wallets
How the malicious Chrome
Once installed, the extension silently activates a continuous monitoring mechanism . It creates automated processes that communicate with remote configuration files on platforms like GitHub, allowing the attacker to change its behavior in real time
This means that even if the extension initially appears harmless, it can dynamically transform into a monitoring or eavesdropping without any notification to the user. Experts point out that such techniques make it particularly difficult to detect the threat.
Stealing ChatGPT conversations and sending them to Discord
The most worrying aspect is the way the extension steals data. When the user visits ChatGPT, malicious code is injected that corrupts the page and records every element of the conversation.
This data is collected into a file and sent via a webhook to the Discord platform , where a bot collects information such as prompts, chat history, and account metadata. This way, attackers gain a complete picture of the user's activity.
See also: NoVoice: New Android malware on Google Play
This practice is particularly dangerous, as AI conversations often include sensitive data, professional information, or personal details.

Suspicious developer profile and possible account breach
The extension is associated with a developer account that is showing unusual activity. The “krittinkalra” profile, which appears to have existed for years, remained inactive for a long time before resurfacing with malware-related content
This sudden change raises suspicions that the account may have been hacked or resold, while its connection to artificial intelligence platforms such as AI4ChatCo and Writecream raises further questions about the security of broader ecosystems.
New threats to the artificial intelligence ecosystem
This case reveals a significant shift in cyberattacks: from exploiting software to exploiting user trust . As AI tools become embedded in everyday life, they become high-value targets for data collection
Attackers no longer need to “break” complex systems; they just need to convince users to install a seemingly useful tool. The use of social engineering and the exploitation of popular platforms make such attacks particularly effective.
See also: PXA Stealer malware campaign from Vietnam exploits LinkedIn
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How can users be protected?
Experts recommend increased caution with extensions that request extensive permissions. Any tool that has access to page content can read or modify data without visible signs.
Additionally, applications should only be installed from trusted sources, and it is important to check the developer's ratings and history. Avoiding third-party tools that interfere between the user and AI services is a key protection measure.
As artificial intelligence becomes an integral part of digital life, the security of conversations takes on new importance. This incident serves as a reminder that convenience should never trump caution, especially when personal and professional data is at stake.
Source: cybersecuritynews.com
