This new malware campaign is stealing chat logs via Chrome extensions



  • Researchers warn of rising “prompt poaching,” where malicious extensions steal AI chatbot conversations
  • Two spoofed Chrome add-ons with ~900K users exfiltrated prompts and tab data every 30 minutes to C2 servers
  • Similar cases (e.g., Urban VPN Proxy) show even highly rated extensions on official stores can harvest chats, credentials, and payment data

A new malicious practice has emerged called “Prompt poaching” – where extensions, add-ons, and other apps, eavesdrop on people’s conversations with AI chatbots and exfiltrate their prompts for various purposes.

This is growing increasingly popular, as researchers find more extensions with hundreds of thousands of users.


https://cdn.mos.cms.futurecdn.net/zAD3N7HhEBrYMu6PimoCfn-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img