Malicious Chrome Extensions Steal ChatGPT Conversations

900K Users Compromised: Chrome Extensions Steal ChatGPT and DeepSeek Conversations

December 30, 2025

7 min read

OX Security discovered two malicious extensions – impersonating the legitimate AITOPIA extension. The malicious extensions exfiltrate ChatGPT and DeepSeek conversations alongside browsing data to attacker-controlled servers. Despite containing data-stealing malware, one of them received Google’s “Featured” badge

TL;DR

The OX Research team detected a new malware campaign stealing ChatGPT and DeepSeek conversations – from over 900,000 Chrome extension downloads. Two malicious extensions were found exfiltrating user conversations and all Chrome tab URLs to a remote C2 server every 30 minutes.

The malware deceives users by impersonating a legitimate extension by a company called AITOPIA, which adds a sidebar on top of any website, with the ability to chat with the most popular LLMs in the market.

The malware adds malicious capabilities by requesting consent for “anonymous, non-identifiable analytics data” while actually exfiltrating complete conversation content from ChatGPT and DeepSeek sessions.

About the Malicious Extensions

We identified two malicious extensions inside this malware campaign, both un-elegantly named:

  1. Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI – with over 600,000 users and a Google Chrome Featured badge
  2. AI Sidebar with Deepseek, ChatGPT, Claude and more – with over 300,000 users.

Potential Damage

The scope of information compromise is significant. Stolen data sent to the threat actor’s C2 server includes:

AI Conversation Data – which could include:

Browsing Activity:

This data can be weaponized for corporate espionage, identity theft, targeted phishing campaigns, or sold on underground forums. Organizations whose employees installed these extensions may have unknowingly exposed intellectual property, customer data, and confidential business information.

Recommendations

Disclosure & Response From Google

We reported both malicious extensions to Google on 29-Dec-2025. As of Dec 30, Google team reached out in response saying the issue is in review.

Both extensions remain live and actively downloadable on the Chrome Web Store, with the first extension still carrying its ‘Featured’ badge.

Attack Analysis

Method: Impersonating a Legitimate Chrome Extension

The original AITOPIA extension adds a sidebar on top of any website, with the ability to chat with the most popular LLMs in the market. AITOPIA details in its privacy policy that users’ chats through the company’s sidebar “will be saved on AITOPIA.ai servers in Amazon US Data server” – this is legitimate behavior with proper disclosure.

The Impersonation Strategy: The threat actors copied the functionality of AITOPIA’s legitimate AI sidebar extension, then added malicious data exfiltration capabilities on top. While the extensions provide the same AI chat sidebar interface that users expect, they contain hidden malware that steals ChatGPT and DeepSeek conversations directly from the browser – functionality absent from the legitimate AITOPIA extension.

This approach serves two purposes: it makes the malicious extensions appear functional and useful (increasing download rates), while the familiar AITOPIA interface masks the malicious activity occurring in the background.

How it Works

The malware leverages broad “read all website content” permissions to monitor user browsing activity. When a user visits ChatGPT or DeepSeek, the extension identifies active conversation pages and extracts both user prompts and AI responses in real-time. This stolen data is stored in a local database on the victim’s machine, then exfiltrated in batches to a remote command-and-control (C2) server every 30 minutes.

Malware Analysis

When the malware is installed, it asks the user for permission to collect anonymized browser behavior. If the user clicks yes, the extension automatically starts to listen to events such as visited URLs, ChatGPT and DeepSeek chats.