Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

0
Medium
News
Published: 08/11/2026 (08/11/2026, 11:15:15 UTC)
Source: SecurityWeek

Description

A Chrome extension named 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was removed from the Chrome Web Store in January 2026 for stealing AI chat data but has since returned. It had over 300,000 installs and a high rating before removal. The extension initially scraped conversation content from AI services and sent it to external domains. After returning, it deployed a new payload that opens affiliate links on update and uninstall events, generating commissions for its operators. The extension is distributed via Google's own CDN and is currently active on enterprise endpoints. Security researchers advise removing the extension due to its malicious behavior and potential for future harmful payloads.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 11:26:21 UTC

Technical Analysis

The Chrome extension 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was initially banned for scraping and stealing conversation data from AI services like ChatGPT and DeepSeek. It amassed significant user adoption before Google removed it in January 2026. The extension later reappeared on the Chrome Web Store with a clean update history to build trust, but subsequent versions introduced a monetization scheme exploiting update and uninstall events to open affiliate links, generating referral commissions. This behavior was detected and blocked by Netskope Threat Labs, which classified the latest version as Trojan.GenericFCA.Script.37952. The extension is distributed via Google's CRX infrastructure and remains active on enterprise endpoints. The developer is listed as Extchange.com, with misleading developer information on the Chrome Store. Netskope recommends removal due to the extension's malicious activities and warns that future updates could carry more damaging payloads.

Potential Impact

The extension compromises user privacy by initially stealing AI chat conversations. Its current payload generates unauthorized affiliate revenue by opening affiliate links on update and uninstall events, potentially exposing users to unwanted web traffic and tracking. The malicious code is distributed through Google's official Chrome Web Store infrastructure, increasing the risk of widespread deployment, including on enterprise endpoints. While the current affiliate scheme is low-stakes, the channel could be used to deliver more harmful payloads in the future.

Defensive Guidance

Organizations and users should remove the 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' extension from all browsers immediately. Security teams should monitor for its presence on endpoints and block related network traffic if possible. Since the extension is distributed via the Chrome Web Store, users should be cautious about reinstalling it. There is no official patch or fix for the extension itself; removal is the recommended mitigation. Vendors and administrators should stay alert for updates or similar malicious extensions appearing in the store.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/","fetched":true,"fetchedAt":"2026-08-11T11:26:13.233Z","wordCount":1185}

Threat ID: 6a7b06d5bf8831d539a0934f

Added to database: 08/11/2026, 11:26:13 UTC

Last enriched: 08/11/2026, 11:26:21 UTC

Last updated: 08/11/2026, 13:38:33 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses