Browser Spy-Ons: Threat Actor's Extension Hijack Your AI Conversations

June 4, 2026, 9:39 a.m.

Description

Multiple malicious Chrome extensions are exploiting the growing use of AI platforms by disguising themselves as legitimate productivity tools while secretly stealing user conversations and personal data. Extensions including Urban VPN, Smart Sidebar, and AI Assistant/Chat AI collectively reach millions of users but contain hidden scripts that intercept communications with popular AI platforms like ChatGPT, Claude, DeepSeek, Gemini, and others. These extensions inject malicious JavaScript that overrides network requests, monitors DOM elements for chat interactions, and exfiltrates sensitive data including conversation content, session identifiers, and timestamps to remote servers. The threat is particularly concerning as users frequently share confidential personal, medical, and corporate information with AI platforms, making intercepted conversations highly valuable for threat actors.

Date

  • Created: June 4, 2026, 2:46 a.m.
  • Published: June 4, 2026, 2:46 a.m.
  • Modified: June 4, 2026, 9:39 a.m.

Indicators

  • c984787ccd787629542da68302ed4ceb48fc7e458eab1c15bf45c3070883d26a
  • 524c953e23ff8b768206cf33a529c11ac5510e47cbf6246db79ee671d1231716
  • f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442