Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Researchers Warn ChatGPT Extensions Steal User Data and Credentials
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Researchers Warn ChatGPT Extensions Steal User Data and Credentials

Highlights

  • Researchers identified 16 malicious Chrome extensions targeting ChatGPT users’ credentials.

  • Extensions exploit web authentication, putting chat histories and linked accounts at risk.

  • Vigilance and review of browser add-ons are advised for better digital safety.

Ethan Moreno
Last updated: 26 January, 2026 - 10:49 pm 10:49 pm
Ethan Moreno 3 hours ago
Share
SHARE

Contents
How Do the Extensions Compromise User Accounts?What Patterns Connect the Extensions?Are Authorities Responding to the Threat?

Browser extensions that promise to make AI tools like ChatGPT even more useful have started attracting unwanted attention from cybercriminals. As productivity-minded users seek add-ons to streamline their ChatGPT experience, a security investigation by LayerX Research uncovered 16 Chrome extensions suspected of targeting users’ account information. The apparent sophistication of these campaigns highlights the challenges in keeping browser-integrated AI interactions secure, especially when new technology enters the mainstream and attackers act quickly to exploit user trust. Digital safety researchers stress the importance of staying vigilant as the lines between convenience and vulnerability blur for millions using generative AI tools daily.

Security warnings about malicious browser extensions have surfaced before, such as during campaigns involving GhostPoster and Roly Poly VPN extensions, which saw download numbers far surpass those seen in the recent ChatGPT-focused incidents. Past events have shown that even low-download extensions can create significant exposure if they gain popularity, particularly by mimicking reputable brands and targeting rapidly-growing platforms. The issue of tactic-sharing among malicious actors has intensified, with synchrony in publishing and backend infrastructure becoming a recognizable pattern. The latest findings echo previous concerns but now involve the unique risks of integrating AI assistants with other sensitive digital environments, expanding potential attack vectors considerably.

How Do the Extensions Compromise User Accounts?

Instead of injecting traditional malware, these extensions exploit weaknesses in ChatGPT’s web authentication, allowing attackers to collect tokens and authorization details from users’ browser sessions. The malicious code monitors outbound requests from the chatgpt.com application and extracts sensitive credentials, which are then relayed to remote servers for later misuse. High privilege and broad access to browser sessions aid these attacks, placing users’ chat histories and linked services—like Slack or GitHub—at risk.

What Patterns Connect the Extensions?

Investigation revealed that all but one of the extensions employed similar techniques. The extensions presented uniform branding elements, shared codebases, and displayed simultaneous upload and update activity. They also utilized common back-end infrastructure, consolidating their activity across multiple Chrome Web Store listings aimed at exploiting legitimate AI workflows for malicious purposes.

Are Authorities Responding to the Threat?

As of now, all 16 flagged extensions remain active on the Chrome Web Store, despite their downloaded numbers remaining comparatively low. Google’s response to these findings hasn’t yet been detailed, but researchers emphasize that even small campaigns can escalate quickly due to the rapidly growing popularity of AI tools. The increased demand for ChatGPT browser integrations fuels the risk of malicious variants gaining traction unnoticed.

“Many of these extensions mimic known brands to gain users’ trust, particularly those designed to enhance interaction with large language models,”

said Natalie Zargarov, the researcher who led the LayerX investigation. She further noted,

“We believe that GPT optimizers will soon become as popular as (if not more than) VPN extensions, which is why we prioritized the publication of this analysis.”

As productivity-driven extensions proliferate, security experts underline the necessity for ongoing vigilance and stricter scrutiny by browser platform providers to limit damage caused by even low-volume campaigns.

The current episode with ChatGPT extensions reflects a recurring struggle between digital productivity and cyber risks. While previous campaigns involving broader extensions managed to capture larger user pools, this campaign demonstrates how attackers shift tactics to align with technology trends. Regular users can reduce exposure by critically evaluating browser extensions and monitoring for unusual account activity, especially when adopting AI-focused tools. Both individual and organizational users stand to benefit from routinely reviewing their extension lists for legitimacy, updating security software, and staying informed about emerging threats as attackers adapt their methods to target widely adopted services.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

NIST Faces Staff Cuts While Accelerating Encryption Validation Efforts

European GCVE Network Launches to Decentralize Vulnerability Tracking

Police Pursue Black Basta Ransomware Figures as Network Faces Setbacks

Cybersecurity Experts Tackle Dilemmas in Ransomware Negotiations

HackerOne Urges Industry to Back Good Faith AI Security Research

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article Goldman Sachs Predicts AI Agents Will Reshape Global Business in 2026
Next Article Ryanair Delays Starlink Wifi Installation as CEO Cites High Costs

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

AAA20 Group Launches CP-66-WD Palletizer for Food Industry Automation
Robotics
Microsoft Gives Authorities BitLocker Keys After Search Warrant
Gaming
Ryanair Delays Starlink Wifi Installation as CEO Cites High Costs
Technology
Goldman Sachs Predicts AI Agents Will Reshape Global Business in 2026
Technology
Experts Reveal How Robotics Advances Shape 2026 Industry Outlook
Robotics
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?