Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious Chrome Extension Steal ChatGPT and DeepSeek Conversations from 900K Users

Two malicious Chrome extensions have been identified, compromising over 900,000 users by extracting ChatGPT and DeepSeek conversations, along with complete browsing histories, to attacker-controlled servers.

Two malicious Chrome extensions have been identified, compromising over 900,000 users by extracting ChatGPT and DeepSeek conversations, along with complete browsing histories, to attacker-controlled servers.

These extensions, discovered by OX Security researchers, mimic the legitimate AITOPIA AI sidebar tool. One of the fake extensions even received Google's "Featured" badge, misleading users about its authenticity.

The OX Research team detected the threat through routine analysis, identifying extensions that replicate AITOPIA's interface for interacting with LLMs such as GPT and Claude.

The extensions, named "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" (600K+ users, ID: fnmihdojmnkclgjpcoonokmkhjpjechg, version 1.9.6) and "AI Sidebar with Deepseek, ChatGPT, Claude and more" (300K+ users, ID: inhcgfpbfdjbjogdfjbclgolkmhnooop), request "anonymous analytics" consent to disguise data theft.

Threat actors host privacy policies on Lovable.dev to obscure their origins, and uninstalled extensions redirect to each other.

Once installed, the extensions monitor browser tabs using the chrome.tabs.onUpdated API, creating a unique "gptChatId" for each victim. When they detect URLs related to chatgpt.com or deepseek.com, they scrape DOM elements for prompts, responses, and session IDs. This data is stored locally, encoded in Base64, and sent in batches to C2 servers such as deepaichats.com or chatsaigpt.com every 30 minutes.

This activity captures proprietary code, business strategies, personally identifiable information (PII), search queries, and internal URLs, which are not covered by AITOPIA's disclosed server storage. The stolen data could expose intellectual property, corporate secrets, and personal data, posing risks of espionage or sale on dark web forums. Additionally, browsing logs may reveal habits, tokens, and organizational structures, facilitating phishing or identity theft .

As of January 7, 2026, both extensions are still available for download. The first extension has been stripped of its "Featured" status following the disclosure, but it was updated as recently as October 2025.

Users are advised to navigate to chrome://extensions, remove extensions by ID, or use the store pages: ChatGPT extension and AI Sidebar. It is recommended to avoid unverified extensions, regardless of badges, and to rely on reputable sources.

These extensions, discovered by OX Security researchers, mimic the legitimate AITOPIA AI sidebar tool.
Kyle Mercer · Thehackingpost

Type Value Notes

Extension name Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI Malicious AI sidebar-style extension

Extension ID fnmihdojmnkclgjpcoonokmkhjpjechg Chrome Web Store ID

Version 1.9.6 Reported malicious build

SHA-256 hash 98d1f151872c27d0abae3887f7d6cb6e4ce29e99ad827cb077e1232bc4a69c00 Package hash

Extension name AI Sidebar with Deepseek, ChatGPT, Claude and more Second malicious extension

Extension ID inhcgfpbfdjbjogdfjbclgolkmhnooop Chrome Web Store ID

Advertisement

Version 1.6.1 Reported malicious build

SHA-256 hash 20ba72e91d7685926c8c1c5b4646616fa9d769e32c1bc4e9f15dddaf3429cea7 Package hash

Category Domain / Endpoint Notes

C2 endpoint deepaichats[.]com Receives stolen chat data and URLs

C2 endpoint chatsaigpt[.]com Additional C2 for exfiltrated data

Lovable-hosted server chataigpt[.]pro Used for privacy policy / infra hosting

Lovable-hosted server chatgptsidebar[.]pro Used for uninstall redirect and infra

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories