Fake AI Browser Extensions: 900,000 Users Hacked — Check Yours in 2 Minutes

Fake AI browser extension secretly leaking data from a Chrome sidebar to an attacker

Over 900,000 people installed what they thought was a helpful ChatGPT sidebar — and instead handed their AI conversations, API keys, and login tokens straight to attackers. That is not a hypothetical. It is what security researchers at OX Security documented in 2026 after tracing two popular Chrome extensions that impersonated legitimate AI assistant tools. One of them had racked up over 600,000 installs and had even earned Google's official "Featured" badge on the Chrome Web Store before it was caught.

If you or your employees use any browser extension that adds an "AI chat sidebar," a "ChatGPT helper," or a "one-click AI assistant" to your browser, this article is for you. We'll walk through exactly how these fake AI extensions work, the real 2026 incidents behind the headlines, a 2-minute audit you can run right now on your own browser, and what to do if you find something suspicious already installed.

A Chrome "Featured" badge is not proof of safety

One of the confirmed malicious AI extensions in 2026 — "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI," with over 600,000 users — had earned Google's official Chrome Web Store "Featured" badge before researchers caught it exfiltrating data. Automated store review cannot catch behavior that only activates after installation or arrives in a later update.

What Actually Happened: The 2026 Fake AI Extension Wave

Fake AI browser extensions are not a new idea — malicious extensions have existed for years, disguised as ad blockers, screenshot tools, and coupon finders. What changed in 2026 is the target: with hundreds of millions of people now using ChatGPT, Claude, DeepSeek, and Gemini every day, an "AI sidebar" extension is one of the most natural-looking things a person can install. Attackers noticed, and built extensions specifically to exploit that trust.

Security researchers at OX Security identified two extensions responsible for the bulk of the exposure: "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" (600,000+ users, Chrome Web Store "Featured" badge) and "AI Sidebar with Deepseek, ChatGPT, Claude and more" (300,000+ users). Together, these two extensions alone accounted for over 900,000 exposed users. In a separate investigation, researchers found 30 additional copycat extensions impersonating AI tools, with a combined 260,000+ downloads, quietly harvesting personal data. Microsoft's Security Blog documented a related wave of malicious AI-assistant extensions harvesting LLM chat histories in March 2026.

The method used by the largest offenders was specific and clever: the malware impersonated the interface of AITOPIA, a legitimate extension that adds an AI chat sidebar to websites. During installation, it requested consent for what it described as "anonymous, non-identifiable analytics data" — language designed to sound harmless. In reality, whenever a user submitted a prompt to ChatGPT or DeepSeek through the sidebar, the extension loaded a hidden full-screen iframe pointing to a server controlled by the attacker. That server intercepted the prompt and captured whatever sensitive information the user had submitted — including email content, other browser content on the page, API keys, and authentication tokens.

Anatomy of the Attack: How a Single Prompt Gets Stolen

To understand why this particular scam is so effective, it helps to walk through what happens on screen versus what happens behind the scenes. From the user's point of view, nothing looks wrong at any point:

  1. Install. The extension appears in a normal Chrome Web Store listing, often with a name almost identical to a real AI tool ("ChatGPT for Chrome," "AI Sidebar," "GPT Assistant"), a plausible icon, and — in the worst confirmed case — an official "Featured" badge.
  2. First launch. A permissions prompt appears, usually worded around "analytics" or "improving your experience." Most users click through this screen in under two seconds, the same way most people accept cookie banners without reading them.
  3. Normal use begins. The extension genuinely does add a working AI chat sidebar. This is the critical design choice that separates a good fake from a bad one — it isn't broken or suspicious-looking, it actually works, which is exactly why nobody suspects it.
  4. The interception. When the user types a prompt and hits enter, the extension silently loads a hidden, full-screen iframe pointing to a domain the attacker controls. That iframe sits between the user and the real AI service, capturing the prompt (and anything else visible on the page — email content, other tabs' data if permissions allow it, session tokens) before or while passing it along.
  5. Exfiltration. The captured data is sent to the attacker's server in the background. There is no visible download, no pop-up, no slowdown severe enough for most users to notice. The chat response still comes back normally, so the interaction feels completely unremarkable.

This is what security researchers mean when they describe this category of malware as "silent" — every visible signal a typical user relies on to judge whether software is safe (does it work? does it look professional? does anything seem broken?) checks out fine. The compromise happens entirely in a layer the user never sees.

Why AI Extensions Became the Perfect Trojan Horse

Browser extension malware has existed for well over a decade, disguised as everything from ad blockers to coupon finders to PDF converters. What makes the 2026 wave different is the target audience and the volume of sensitive material flowing through it. A few factors line up almost perfectly for attackers:

Not sure what's hiding in your browser?

Our certified bilingual tech remotes in, audits every extension and startup process on your PC or Mac, and removes anything malicious — same day, from $119.99. No fix, no fee.

Why This Is Worse Than a Normal Data Breach

When a website gets breached, attackers typically get a database of passwords or account details. When a fake AI extension steals your data, they get something arguably more valuable: the raw content of everything you typed into an AI chat, in context, in your own words. People paste extremely sensitive material into ChatGPT and Claude every day without thinking twice — draft contracts, unpublished financial numbers, customer lists, medical questions, source code, API keys they're debugging, even full email threads pasted in for "help me reply to this." A fake extension sitting on top of that conversation captures all of it, unfiltered.

For a business, the fallout goes further than one employee's inconvenience. Stolen data of this kind can be weaponized for corporate espionage, identity theft, or highly convincing targeted phishing campaigns built from real internal details — or simply sold in bulk on underground forums. An employee who installed one of these extensions on a work laptop may have unknowingly exposed intellectual property, customer data, and confidential business information without a single "official" breach ever touching the company's own systems.

Common Categories of Fake AI Extensions to Watch For

Not every risky AI extension looks like a "ChatGPT sidebar." The category has expanded to cover several distinct product types, each with its own reason to request broad permissions:

A

AI chat sidebars and "one-click assistants"

The category behind the 900,000-user incident. These add a floating chat panel to every website you visit, and typically request the broadest permissions of any AI extension type — which is also the category where that access is hardest to justify.

B

AI writing/grammar assistants

These need access to text fields across the web to function legitimately (similar to Grammarly), which makes it genuinely hard to tell a legitimate tool from a data-harvesting one based on permissions alone. Reputation and developer identity matter more here than for any other category.

C

"AI summarizer" / "AI reader" tools

Marketed as a way to summarize long articles or PDFs with one click. Because they need to read page content to work, a summarizer with broad permissions doesn't look unusual — even when it's exfiltrating far more than a summary needs.

D

Fake AI image/video generator shortcuts

Extensions promising to generate AI images or videos "right from your browser" without ever opening the real tool's website. Several confirmed cases in 2026 used this pitch purely as bait — the "generator" either does nothing useful or silently forwards browsing data while displaying a fake loading spinner.

Sign Likely legitimate AI extension Likely malicious AI extension
Developer identity Named, verifiable company with a real website and support contact Anonymous publisher, generic name, no verifiable company
Permissions requested Access limited to the AI tool's own site, or clearly explained "Read and change all your data on all websites" with no clear reason
Reviews Mix of detailed, dated, specific reviews over time Bursts of generic 5-star reviews posted close together
Store badges Helpful signal, but not proof on its own Can still be present — a "Featured" badge does not guarantee safety
What it asks you to do first Works after a simple install and login to the official AI service Asks you to "accept analytics" or grant broad access before doing anything useful

What a Stolen AI Conversation Can Actually Reveal

It's worth being concrete about what ends up in a typical AI chat history, because the abstract phrase "data was exposed" understates the problem. In a normal week of use, a single person's AI chat log can contain:

None of this requires unusual behavior on the user's part — it's simply how people use AI chat tools day to day, at work and at home. That's exactly why a compromised AI extension is so much more damaging than a compromised ad-blocker: the "product" it sits on top of is specifically the place where people paste their most sensitive, unfiltered material, on the reasonable assumption that the conversation stays between them and the AI provider.

The 2-Minute Audit: Check Your Own Browser Right Now

1

Open your extensions list

Type chrome://extensions into your address bar and press Enter. On Microsoft Edge, use edge://extensions. On Firefox, use about:addons. This shows every extension currently installed, whether or not it has an icon visible in your toolbar.

2

Identify every AI-related extension

Look for anything related to ChatGPT, Claude, Gemini, DeepSeek, "AI sidebar," "AI writer," "AI chat assistant," or similar. Many of these get installed months ago and forgotten — that's exactly the kind of extension attackers rely on going unnoticed.

3

Click "Details" and review the permissions

Every extension lists what it can access. The single biggest red flag is "Read and change all your data on all websites." A simple AI chat sidebar rarely needs this level of access to every site you visit — legitimate tools scope their access to the AI service's own domain wherever possible.

4

Check the developer and the Chrome Web Store listing

Click through to the store page. Is the developer a real, named company, or an anonymous publisher? Does the support link go anywhere real? Read a sample of the reviews — a wall of generic five-star reviews posted in a short window is a common sign of a fabricated reputation.

5

Remove anything you don't fully recognize or trust

Click Remove. Don't just disable it — fully uninstall it. When in doubt, remove it; you can always reinstall a legitimate tool later once you've verified it independently.

6

Restart your browser completely

Close all browser windows (not just the tab) and reopen. This clears any active malicious scripts or iframes that may still be running in memory from a removed extension.

7

Rotate anything you typed while the extension was active

Change your email and banking passwords first, then any others you use regularly. Regenerate any API keys, tokens, or credentials you typed, pasted, or had visible on screen since installing the extension — treat all of it as potentially exposed.

8

Check your accounts for unfamiliar activity

Review recent sign-in activity on your email, cloud storage, and any AI tool accounts. Look for sent emails you didn't send, new devices in your login history, or account recovery emails you didn't request.

9

Run a full malware scan

A malicious extension is one entry point, but it's worth confirming nothing else came along with it. Run a full scan with Windows Defender, Malwarebytes, or your existing antivirus, and check installed browser add-ons on every browser you use, not just your default one.

10

Tell your IT team if this happened on a work device

If the extension was on a laptop used for work, don't handle it quietly and move on. Notify whoever manages IT/security so any business accounts, customer data, or shared drives the device had access to can be checked and, if needed, credentials rotated organization-wide.

Extensions can turn malicious after you install them

Browser extensions auto-update by default. An extension can be perfectly safe on install day and be sold to a new owner, or quietly updated with malicious code, months later — while you never see a prompt or notice anything changed. This is why a periodic audit (not just a one-time check) matters, especially for any extension with broad site permissions.

Set a recurring reminder — quarterly is a reasonable cadence for a personal device, monthly for a business-managed one — to repeat this same 2-minute audit. It takes less time than reading this paragraph, and it's the single highest-value habit anyone can adopt against this specific category of threat. Pair it with checking your password manager's built-in breach monitoring (most major password managers now flag exposed credentials automatically) so that even if an extension does slip through, you find out quickly rather than months later.

Do You Even Need an AI Browser Extension?

Before deciding which extension to trust, it's worth asking a more basic question: do you need one at all? The honest answer for most people is no. ChatGPT, Claude, Gemini, and DeepSeek all work as full, feature-complete websites without any extension installed. A sidebar extension typically saves you the trouble of opening a new tab — a convenience worth weighing against the fact that, as this article demonstrates, it also hands a third party a standing position between you and every AI conversation you have.

If you genuinely want in-browser AI convenience without installing a third-party extension, a few lower-risk paths exist:

None of this means every third-party AI extension is dangerous — plenty are built by legitimate small developers with no ill intent. But given that even a Chrome "Featured" badge was insufficient to catch a 600,000-user malicious extension in 2026, the safest default for anyone handling sensitive information is to minimize the number of pieces of software sitting between you and your AI conversations, not maximize convenience.

How Businesses Should Govern AI Extension Installs

For a small or medium business, relying on every employee to individually spot a fake AI extension is not a real security strategy — it's a coin flip repeated across every laptop in the company. A handful of practical controls close most of this gap without needing an enterprise security budget:

None of these controls require enterprise-grade tooling or a dedicated security hire. A five-person accounting firm and a fifty-person marketing agency can both put an extension allowlist in place using the browser management console that's already included with their existing Microsoft 365 or Google Workspace business subscription — the gap is usually awareness, not budget. If your business doesn't currently have anyone responsible for reviewing what software (including browser extensions) gets installed on company devices, that's the single highest-leverage fix available, and it costs nothing but a policy decision.

What to Tell Employees in One Sentence

Security training works best when it's memorable rather than comprehensive. If you only communicate one rule about this topic to your team, make it this: never install a browser extension that promises AI features unless you can name the company that built it. "ChatGPT," "Claude," and "Gemini" are products, not permission to trust any extension that mentions them — the real AI tools work perfectly well as regular websites, with no extension required for the vast majority of everyday use.

Think you might already be affected?

IT Cares offers a full remote security check: extension audit, malware scan, credential exposure review, and cleanup — for individuals and businesses across Canada and the US. Most sessions completed same-day.

Bottom Line

The 900,000-user incident is not a one-time fluke — it's a preview of where this category of threat is heading as long as AI tools remain as popular as they are. New copycat extensions get published faster than store review teams can catch them, and a convincing name plus a working feature is often enough to earn hundreds of thousands of installs before anyone notices something is wrong. The good news is that defending against this specific threat doesn't require deep technical skill: a two-minute permission check, a habit of favoring first-party integrations over anonymous third-party extensions, and a quarterly re-audit cover the overwhelming majority of the risk described in this article.

Frequently Asked Questions

How do fake AI browser extensions actually steal your data?

Most request broad permissions ("read and change all your data on all websites") under the guise of an AI chat sidebar. When you type a prompt into ChatGPT, Claude, or another AI tool, the extension intercepts it — in documented 2026 cases, some loaded a hidden full-screen iframe pointing to an attacker-controlled server that captured the complete conversation, including email content, browser content, API keys, and login tokens visible on the page.

Were real companies affected by fake AI extension malware in 2026?

Yes. OX Security documented over 900,000 Chrome users exposed by extensions masquerading as legitimate AI productivity tools, including one with 600,000+ users that had earned a Google Chrome "Featured" badge. A separate investigation found 30 copycat extensions with a combined 260,000+ downloads, and Microsoft's Security team documented related malicious AI-assistant extensions in a March 2026 report.

How can I tell if a Chrome extension is a fake AI tool before installing it?

Check the developer identity, the permissions requested (a simple AI sidebar should not need to read and change all your data on all websites), and the review pattern (generic reviews posted in a short burst is a red flag). A Chrome "Featured" badge is not proof of safety — at least one confirmed 2026 malicious extension had earned that badge.

What should I do if I already installed a malicious AI extension?

Remove it immediately from chrome://extensions, restart your browser, then change your passwords (starting with email and banking) and regenerate any API keys or tokens you used while it was active. Check your accounts for unfamiliar activity, and notify your IT team if it happened on a work device.

Are AI browser extensions from the official Chrome Web Store always safe?

No. Being listed on the official store, even with a "Featured" badge, does not guarantee safety — automated review can miss malicious behavior that only activates after install or arrives in a later update. Documented 2026 cases involved extensions with hundreds of thousands of installs that were live on the official store before being caught.

Can a fake AI extension steal my saved browser passwords too, not just AI chats?

It depends on the permissions granted, but an extension with "read and change all your data on all websites" access can potentially see anything on any page you visit while active — including text typed into login forms and session cookies, not just AI chat content. That broad permission level is the single biggest red flag to check for during an audit.

Can a previously safe extension become malicious after an update?

Yes. Extensions typically auto-update silently with no prompt shown to the user. A tool can be genuinely safe on install day and have malicious code introduced later, either through a compromised update or after being sold to a new owner. That's why a periodic re-check matters more than a one-time review, especially for anything with broad site permissions.

Comments (3)

MT
Mireille T., Laval
August 3, 2026

Ran the 2-minute audit on my work laptop and found an "AI Sidebar" extension I genuinely don't remember installing, with full "read and change all your data" access. Removed it and rotated my passwords same night. Terrifying how normal it looked in the toolbar.

DL
David L., Ottawa
August 2, 2026

The part about the Chrome "Featured" badge really stuck with me — I always assumed that meant Google had vetted it. Had IT Cares do a full extension + credential audit for our small team after reading this, glad we caught nothing but good to be sure.

SB
Sophie B., Gatineau
August 1, 2026

I paste client contract drafts into ChatGPT constantly. Never thought about what extension might be sitting between me and the actual site until now. Cleaned up my extensions list, only kept two I could actually verify.

Leave a Comment