Malicious AI Assistant Extensions Harvest LLM Chat Histories
A malicious browser extension campaign with nearly 900,000 installs targeted users of LLM platforms like ChatGPT and DeepSeek, harvesting chat histories and browsing data across more than 20,000 enterprise tenants. This campaign demonstrates an emerging attack vector exploiting the popularity of AI assistants through compromised browser extensions. The threat highlights significant data exposure risks in enterprise environments using generative AI tools.
Summary
A malicious browser extension campaign with nearly 900,000 installs targeted users of LLM platforms like ChatGPT and DeepSeek, harvesting chat histories and browsing data across more than 20,000 enterprise tenants. This campaign demonstrates an emerging attack vector exploiting the popularity of AI assistants through compromised browser extensions. The threat highlights significant data exposure risks in enterprise environments using generative AI tools.