Thirty fake AI extensions in Chrome harvested user data
Researchers at LayerX have found 30 Chrome extensions that pose as add-ons for well-known AI services while collecting email addresses and user data. They carry plausible names such as ChatGPT Sidebar, Grok Chatbot and Ask Gemini, but share a common backend and code structure. By placing most of the code in a full-page iframe, the authors avoided the checks Google performs server-side. Users received a plausible answer, while their questions and the responses were proxied through the operators' own infrastructure. More than 260,000 users have installed the extensions, several of which gathered positive reviews and were even featured in the Chrome Web Store.
What this means for your organisation
Employees experimenting with AI tools on their own tend to install an extension because it looks official and sits in the official store. Work-related questions, and whatever is pasted into them, then pass through a third party you have no relationship with. This is shadow AI in practice, and it grows fastest where the organisation has not offered an approved alternative.
Berigo recommends
- Pull an inventory of installed browser extensions from endpoint management and look specifically for AI-related names.
- Move to an allow-list for browser extensions in policy rather than blocking individual cases as they surface.
- Give staff an approved AI tool with clear rules on what may be pasted into it, so the need is met inside the organisation.
- Assess whether data may have been exposed during the period, and what kind of information was pasted in.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch