A Chrome extension previously removed for stealing AI chatbot conversations has reappeared in the Chrome Web Store and resumed malicious behavior. The extension, identified as "AI Sidebar with DeepSeek AI" and also described as "AI Sidebar with DeepSeek, ChatGPT, Claude and more," had earlier been reported scraping ChatGPT and DeepSeek conversations and sending that data to attacker-controlled domains. OX Security said the extension had amassed more than 300,000 installs before Google removed it, but Netskope found it was later relisted and again distributed through Google’s CRX infrastructure.
Netskope reported the operator used a clean-then-poison update chain: version 1.7.2.0 appeared benign, while version 1.7.3.0 introduced code that silently opened affiliate links during extension updates and on uninstall, replacing the earlier chat-exfiltration logic with affiliate fraud and uninstall-URL hijacking. The malicious build, tied to extension ID inhcgfpbfdjbjogdfjbclgolkmhnooop, was still being downloaded daily, and enterprise security tools detected it as Trojan.GenericFCA.Script.37952. Researchers warned that the more serious issue is the supply-chain risk of a previously delisted publisher regaining Chrome Web Store distribution and using Google’s update channel to push malicious code again.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In August 2026, Netskope Threat Labs detected and blocked version 1.7.3.0 arriving on enterprise endpoints via Google's CRX/CDN infrastructure and classified it as Trojan.GenericFCA.Script.37952. Netskope also reported the extension to the Chrome Web Store and advised organizations to remove it.
As of August 2026, the extension was active again on the Chrome Web Store despite its earlier removal. Netskope said relisting was the primary driver of new infections, with auto-update acting as a secondary driver.
In July 2026, the extension resumed shipping code to enterprise endpoints with version 1.7.3.0, which added a 21-line monetization payload to trigger affiliate-link openings on update and uninstall. This build no longer contained the earlier AI conversation exfiltration logic, replacing it with affiliate fraud behavior.
Version 1.7.2.0 of the extension was distributed from July 20 to July 31, 2026. Netskope assessed this build as clean functionality intended to rebuild trust and establish a benign update history.
Google removed the Chrome extension from the Chrome Web Store in January 2026 over allegations that it was stealing AI conversation data. The extension had been marketed as an AI assistant for Chrome.
In December 2025, OX Security published research showing that earlier versions of the Chrome extension scraped ChatGPT and DeepSeek conversation content and sent it to attacker-controlled domains. The extension had amassed more than 300,000 installs and a 4.6-star rating before later removal.
The domain Extchange.com, later referenced in the extension files as the developer and data controller, was registered in February 2024. The registrant details were not publicly disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcenetskope.com
Open sourceox.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.