Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
A Chrome extension named 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was removed from the Chrome Web Store in January 2026 for stealing AI chat data but has since returned. It had over 300,000 installs and a high rating before removal. The extension initially scraped conversation content from AI services and sent it to external domains. After returning, it deployed a new payload that opens affiliate links on update and uninstall events, generating commissions for its operators. The extension is distributed via Google's own CDN and is currently active on enterprise endpoints. Security researchers advise removing the extension due to its malicious behavior and potential for future harmful payloads.
AI Analysis
Technical Summary
The Chrome extension 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was initially banned for scraping and stealing conversation data from AI services like ChatGPT and DeepSeek. It amassed significant user adoption before Google removed it in January 2026. The extension later reappeared on the Chrome Web Store with a clean update history to build trust, but subsequent versions introduced a monetization scheme exploiting update and uninstall events to open affiliate links, generating referral commissions. This behavior was detected and blocked by Netskope Threat Labs, which classified the latest version as Trojan.GenericFCA.Script.37952. The extension is distributed via Google's CRX infrastructure and remains active on enterprise endpoints. The developer is listed as Extchange.com, with misleading developer information on the Chrome Store. Netskope recommends removal due to the extension's malicious activities and warns that future updates could carry more damaging payloads.
Potential Impact
The extension compromises user privacy by initially stealing AI chat conversations. Its current payload generates unauthorized affiliate revenue by opening affiliate links on update and uninstall events, potentially exposing users to unwanted web traffic and tracking. The malicious code is distributed through Google's official Chrome Web Store infrastructure, increasing the risk of widespread deployment, including on enterprise endpoints. While the current affiliate scheme is low-stakes, the channel could be used to deliver more harmful payloads in the future.
Mitigation Recommendations
Organizations and users should remove the 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' extension from all browsers immediately. Security teams should monitor for its presence on endpoints and block related network traffic if possible. Since the extension is distributed via the Chrome Web Store, users should be cautious about reinstalling it. There is no official patch or fix for the extension itself; removal is the recommended mitigation. Vendors and administrators should stay alert for updates or similar malicious extensions appearing in the store.
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
Description
A Chrome extension named 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was removed from the Chrome Web Store in January 2026 for stealing AI chat data but has since returned. It had over 300,000 installs and a high rating before removal. The extension initially scraped conversation content from AI services and sent it to external domains. After returning, it deployed a new payload that opens affiliate links on update and uninstall events, generating commissions for its operators. The extension is distributed via Google's own CDN and is currently active on enterprise endpoints. Security researchers advise removing the extension due to its malicious behavior and potential for future harmful payloads.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Chrome extension 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was initially banned for scraping and stealing conversation data from AI services like ChatGPT and DeepSeek. It amassed significant user adoption before Google removed it in January 2026. The extension later reappeared on the Chrome Web Store with a clean update history to build trust, but subsequent versions introduced a monetization scheme exploiting update and uninstall events to open affiliate links, generating referral commissions. This behavior was detected and blocked by Netskope Threat Labs, which classified the latest version as Trojan.GenericFCA.Script.37952. The extension is distributed via Google's CRX infrastructure and remains active on enterprise endpoints. The developer is listed as Extchange.com, with misleading developer information on the Chrome Store. Netskope recommends removal due to the extension's malicious activities and warns that future updates could carry more damaging payloads.
Potential Impact
The extension compromises user privacy by initially stealing AI chat conversations. Its current payload generates unauthorized affiliate revenue by opening affiliate links on update and uninstall events, potentially exposing users to unwanted web traffic and tracking. The malicious code is distributed through Google's official Chrome Web Store infrastructure, increasing the risk of widespread deployment, including on enterprise endpoints. While the current affiliate scheme is low-stakes, the channel could be used to deliver more harmful payloads in the future.
Defensive Guidance
Organizations and users should remove the 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' extension from all browsers immediately. Security teams should monitor for its presence on endpoints and block related network traffic if possible. Since the extension is distributed via the Chrome Web Store, users should be cautious about reinstalling it. There is no official patch or fix for the extension itself; removal is the recommended mitigation. Vendors and administrators should stay alert for updates or similar malicious extensions appearing in the store.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/","fetched":true,"fetchedAt":"2026-08-11T11:26:13.233Z","wordCount":1185}
Threat ID: 6a7b06d5bf8831d539a0934f
Added to database: 08/11/2026, 11:26:13 UTC
Last enriched: 08/11/2026, 11:26:21 UTC
Last updated: 08/11/2026, 13:38:33 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.