Google-Featured Fake Extension Steals 900K Chats
A malicious campaign involving a Google-featured fake extension has compromised more than 900,000 Chrome users, according to researchers at OX Security. Two rogue browser add-ons, disguised as AI chat assistants, secretly collected conversations from ChatGPT and DeepSeek, as well as users’ full browsing histories.
The fake extensions cloned the interface of AITOPIA, a legitimate AI tool. One even received Google’s “Featured” badge, adding to its credibility. Once installed, the malware monitored browser activity, extracted chat contents and session data, then exfiltrated it every 30 minutes to attacker-controlled servers like deepaichats.com.
The stolen data includes proprietary code, business plans, and personal identifiers, which could fuel espionage and phishing attacks. Users also risk exposure of sensitive searches and enterprise structure.
As of early 2026, the extensions remain live on the Chrome Web Store. One recently lost its “Featured” status but continues operating. Users should delete any extensions tied to the google-featured fake extension campaign immediately.
Read the full report: https://cybersecuritynews.com/malicious-chrome-extension-steal-data/
