Skip to content

Defense Digests

Malicious Browser Extensions Steal ChatGPT & DeepSeek Chat Logs from Users 

d3

Table of content

Executive Summary 

Two Chrome extensions posing as AI productivity helpers were found exfiltrating users’ sensitive ChatGPT and DeepSeek conversations to attacker-controlled servers. The extensions abused browser permissions to capture complete chatbot histories, browsing data, internal corporate URLs, and authentication tokens, putting both personal and company data at risk. This recent threat demonstrates two of the latest attacker trends of creating imposter AI tools through an often unprotected vector of browser extensions. 

Details 

Security researchers uncovered the two malicious Chrome Web Store extensions with a combined install count exceeding 900,000 users. The extensions were masquerading as legitimate AI productivity tools with names including “Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI” (over 600,000 installs) and “AI Sidebar with DeepSeek, ChatGPT, Claude and more” (over 300,000 installs). 

Once installed, the extensions will prompt users to grant “anonymous, non-identifiable analytics data” permissions. After consent, the victim’s private chat history and data relating to open tabs, browser history, and active sessions are stored locally before being sent to the attacker’s command and control infrastructure. 

Impacts 

  • Exposure of sensitive AI chat content, including confidential business data, source code, and internal procedures entered into legitimate AI tools.​ 
  • Leakage of internal URLs and application links, revealing details about corporate environments, tooling, and infrastructure that can aid future targeted attacks.​ 
  • Potential theft of authentication tokens or session identifiers associated with visited web applications, increasing risk of account takeover.​ 
  • Increased likelihood of tailored phishing, social engineering, and business email compromise using stolen chat context and browsing patterns.​ 
  • Regulatory and compliance exposure if AI chats include regulated data such as customer PII, financial transactions, health records or other protected information.​ 

Mitigation Strategies 

  1. Block all indicators of the malicious software, below, in your Endpoint Detection & Response (EDR) and web content filtering tools. 
  1. Implement technical restrictions requiring administrators to consent to the download of any browser extensions. 
  1. Create corporate policy around acceptable usage of AI tools and document an approved list. Users can then be restricted to only accessing allowed AI platforms. 
  1. Educate users about the novel threats of AI usage, secure data handling, and the malicious impersonation of legitimate applications. 

Indicators of Compromise (IoCs) 

Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI 

  • Extension ID: fnmihdojmnkclgjpcoonokmkhjpjechg 
  • Version: 1.9.6 
  • SHA-256: 98d1f151872c27d0abae3887f7d6cb6e4ce29e99ad827cb077e1232bc4a69c00 

AI Sidebar with Deepseek, ChatGPT, Claude, and more 

  • Extension ID: inhcgfpbfdjbjogdfjbclgolkmhnooop 
  • Version: 1.6.1 
  • SHA-256: 20ba72e91d7685926c8c1c5b4646616fa9d769e32c1bc4e9f15dddaf3429cea7 

Command & Control (C2) Domains 

  • deepaichats[.]com 
  • chatsaigpt[.]com 
  • chataigpt[.]pro 
  • chatgptsidebar[.]pro 
  • deepseek[.]ai 
  • chatgptbuddy[.]com 

Contributing Author:  Sam McGovern | Associate vCISO

Recent Tweets

INSIGHTS

Learn about the latest threats and vulnerabilities with our D3 alerts.

Subscribe to get real-time notifications when a new Dataprise Defense Digest is published.