Malicious Chrome Extensions Steal ChatGPT Conversations
900K Users Compromised: Chrome Extensions Steal ChatGPT and DeepSeek Conversations
December 30, 2025
7 min read
OX Security discovered two malicious extensions – impersonating the legitimate AITOPIA extension. The malicious extensions exfiltrate ChatGPT and DeepSeek conversations alongside browsing data to attacker-controlled servers. Despite containing data-stealing malware, one of them received Google’s “Featured” badge
TL;DR
The OX Research team detected a new malware campaign stealing ChatGPT and DeepSeek conversations – from over 900,000 Chrome extension downloads. Two malicious extensions were found exfiltrating user conversations and all Chrome tab URLs to a remote C2 server every 30 minutes.
The malware deceives users by impersonating a legitimate extension by a company called AITOPIA, which adds a sidebar on top of any website, with the ability to chat with the most popular LLMs in the market.
The malware adds malicious capabilities by requesting consent for “anonymous, non-identifiable analytics data” while actually exfiltrating complete conversation content from ChatGPT and DeepSeek sessions.
About the Malicious Extensions
We identified two malicious extensions inside this malware campaign, both un-elegantly named:
- Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI – with over 600,000 users and a Google Chrome Featured badge
- AI Sidebar with Deepseek, ChatGPT, Claude and more – with over 300,000 users.
Potential Damage
The scope of information compromise is significant. Stolen data sent to the threat actor’s C2 server includes:
AI Conversation Data – which could include:
- Proprietary source code and development queries shared with ChatGPT or DeepSeek
- Business strategies, competitive intelligence, and strategic planning discussions
- Personal identifiable information (PII) disclosed during conversations
- Confidential research, legal matters, and sensitive corporate communications
Browsing Activity:
- Complete URLs from all Chrome tabs, exposing the user’s browsing profile
- Search queries containing sensitive keywords and research topics
- URL parameters that may contain session tokens, user IDs, and authentication data
- Internal corporate URLs revealing organizational structure and tools
This data can be weaponized for corporate espionage, identity theft, targeted phishing campaigns, or sold on underground forums. Organizations whose employees installed these extensions may have unknowingly exposed intellectual property, customer data, and confidential business information.
Recommendations
- If you have downloaded one of the affected Chrome extensions, immediately remove them from your browser.
- Go to either of the extension pages, and check if you have the “Remove from Chrome” button
- Another way to remove the extensions is to copy paste “chrome://extensions” into your browser, and remove them directly from there.
- Do not install extensions from unknown sources, even if they have the “Featured” tag on them.
Disclosure & Response From Google
We reported both malicious extensions to Google on 29-Dec-2025. As of Dec 30, Google team reached out in response saying the issue is in review.
Both extensions remain live and actively downloadable on the Chrome Web Store, with the first extension still carrying its ‘Featured’ badge.
Attack Analysis
Method: Impersonating a Legitimate Chrome Extension
The original AITOPIA extension adds a sidebar on top of any website, with the ability to chat with the most popular LLMs in the market. AITOPIA details in its privacy policy that users’ chats through the company’s sidebar “will be saved on AITOPIA.ai servers in Amazon US Data server” – this is legitimate behavior with proper disclosure.
The Impersonation Strategy: The threat actors copied the functionality of AITOPIA’s legitimate AI sidebar extension, then added malicious data exfiltration capabilities on top. While the extensions provide the same AI chat sidebar interface that users expect, they contain hidden malware that steals ChatGPT and DeepSeek conversations directly from the browser – functionality absent from the legitimate AITOPIA extension.
This approach serves two purposes: it makes the malicious extensions appear functional and useful (increasing download rates), while the familiar AITOPIA interface masks the malicious activity occurring in the background.
How it Works
The malware leverages broad “read all website content” permissions to monitor user browsing activity. When a user visits ChatGPT or DeepSeek, the extension identifies active conversation pages and extracts both user prompts and AI responses in real-time. This stolen data is stored in a local database on the victim’s machine, then exfiltrated in batches to a remote command-and-control (C2) server every 30 minutes.
Malware Analysis
When the malware is installed, it asks the user for permission to collect anonymized browser behavior. If the user clicks yes, the extension automatically starts to listen to events such as visited URLs, ChatGPT and DeepSeek chats.