Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek .
AI Analysis
Technical Summary
The Chrome extension 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was initially banned for scraping and stealing conversation data from AI services like ChatGPT and DeepSeek. It amassed significant user adoption before Google removed it in January 2026. The extension later reappeared on the Chrome Web Store with a clean update history to build trust, but subsequent versions introduced a monetization scheme exploiting update and uninstall events to open affiliate links, generating referral commissions. This behavior was detected and blocked by Netskope Threat Labs, which classified the latest version as Trojan.GenericFCA.Script.37952. The extension is distributed via Google's CRX infrastructure and remains active on enterprise endpoints. The developer is listed as Extchange.com, with misleading developer information on the Chrome Store. Netskope recommends removal due to the extension's malicious activities and warns that future updates could carry more damaging payloads.
Potential Impact
The extension compromises user privacy by initially stealing AI chat conversations. Its current payload generates unauthorized affiliate revenue by opening affiliate links on update and uninstall events, potentially exposing users to unwanted web traffic and tracking. The malicious code is distributed through Google's official Chrome Web Store infrastructure, increasing the risk of widespread deployment, including on enterprise endpoints. While the current affiliate scheme is low-stakes, the channel could be used to deliver more harmful payloads in the future.
Mitigation Recommendations
Organizations and users should remove the 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' extension from all browsers immediately. Security teams should monitor for its presence on endpoints and block related network traffic if possible. Since the extension is distributed via the Chrome Web Store, users should be cautious about reinstalling it. There is no official patch or fix for the extension itself; removal is the recommended mitigation. Vendors and administrators should stay alert for updates or similar malicious extensions appearing in the store.
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
Description
The extension amassed over 300,000 installs and a 4.6 rating before Google removed it for stealing data. The post Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Chrome extension 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' was initially banned for scraping and stealing conversation data from AI services like ChatGPT and DeepSeek. It amassed significant user adoption before Google removed it in January 2026. The extension later reappeared on the Chrome Web Store with a clean update history to build trust, but subsequent versions introduced a monetization scheme exploiting update and uninstall events to open affiliate links, generating referral commissions. This behavior was detected and blocked by Netskope Threat Labs, which classified the latest version as Trojan.GenericFCA.Script.37952. The extension is distributed via Google's CRX infrastructure and remains active on enterprise endpoints. The developer is listed as Extchange.com, with misleading developer information on the Chrome Store. Netskope recommends removal due to the extension's malicious activities and warns that future updates could carry more damaging payloads.
Potential Impact
The extension compromises user privacy by initially stealing AI chat conversations. Its current payload generates unauthorized affiliate revenue by opening affiliate links on update and uninstall events, potentially exposing users to unwanted web traffic and tracking. The malicious code is distributed through Google's official Chrome Web Store infrastructure, increasing the risk of widespread deployment, including on enterprise endpoints. While the current affiliate scheme is low-stakes, the channel could be used to deliver more harmful payloads in the future.
Defensive Guidance
Organizations and users should remove the 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' extension from all browsers immediately. Security teams should monitor for its presence on endpoints and block related network traffic if possible. Since the extension is distributed via the Chrome Web Store, users should be cautious about reinstalling it. There is no official patch or fix for the extension itself; removal is the recommended mitigation. Vendors and administrators should stay alert for updates or similar malicious extensions appearing in the store.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/extension-banned-for-stealing-ai-chats-returns-to-chrome-store-resumes-malicious-activities/","fetched":true,"fetchedAt":"2026-08-11T11:26:13.233Z","wordCount":1185}
Threat ID: 6a7b06d5bf8831d539a0934f
Added to database: 08/11/2026, 11:26:13 UTC
Last enriched: 08/11/2026, 11:26:21 UTC
Last updated: 09/22/2026, 15:26:14 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.