{"id":11709,"date":"2026-03-30T10:04:09","date_gmt":"2026-03-30T10:04:09","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/30\/new-prompt-poaching-attack-steals-users-ai-conversations-via-malicious-browser-extensions\/"},"modified":"2026-03-30T10:04:09","modified_gmt":"2026-03-30T10:04:09","slug":"new-prompt-poaching-attack-steals-users-ai-conversations-via-malicious-browser-extensions","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/30\/new-prompt-poaching-attack-steals-users-ai-conversations-via-malicious-browser-extensions\/","title":{"rendered":"New \u201cPrompt Poaching\u201d Attack Steals Users\u2019 AI Conversations via Malicious Browser Extensions"},"content":{"rendered":"<p>    New \u201cPrompt Poaching\u201d Attack Steals Users\u2019 AI Conversations via Malicious Browser Extensions<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>For many users, engaging with an AI assistant requires opening a dedicated browser tab, which inherently isolates the AI from other browsing activities. While this separation improves privacy, it reduces usefulness and context.<\/p>\n<p>To bridge this gap, <a href=\"https:\/\/cybersecuritynews.com\/microsoft-warns-fake-ai-browser-extensions-compromised-chat-histories\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI-powered browser extensions<\/a> have surged in popularity, allowing AI agents to seamlessly interact with emails, corporate portals, and personal documents across multiple tabs.<\/p>\n<p>However, this convenience introduces a dangerous trade-off. Expel uncovered a new threat dubbed \u201cprompt poaching,\u201d in which malicious browser extensions silently monitor, copy, and exfiltrate sensitive AI conversations without user consent.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-prompt-poaching-attack\">\n<strong>Prompt Poaching<\/strong> <strong>Attack<\/strong><br \/>\n<\/h2>\n<p>Security researchers have recently responded to dozens of <a href=\"https:\/\/cybersecuritynews.com\/chrome-extensions-exfiltrate-browsing-history\/\" target=\"_blank\" rel=\"noreferrer noopener\">incidents involving Chrome extensions<\/a> secretly harvesting user interactions with AI assistants.<\/p>\n<p>The mechanics of prompt poaching are straightforward but highly effective. Once installed, these rogue extensions actively monitor open browser tabs.<\/p>\n<p>When they detect a loaded AI client, they utilize <a href=\"https:\/\/cybersecuritynews.com\/gcore-radar-report-reveals-150-surge-in-ddos-attacks-year-on-year\/\" target=\"_blank\" rel=\"noreferrer noopener\">API interception or DOM scraping techniques<\/a> to capture both the user\u2019s inputs and the AI\u2019s responses.<\/p>\n<p>The extension then packages this collected data and quietly transmits it to external command-and-control servers operated by the developers.<\/p>\n<p>Threat actors deploy these malicious capabilities through two primary vectors. The first method involves cloning popular, legitimate extensions and injecting them with <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-clickfix-technique-to-deploy-remote-access-trojans\/\" target=\"_blank\" rel=\"noreferrer noopener\">data-stealing code<\/a>.<\/p>\n<p>For example, attackers have successfully distributed several malicious clones of tools originally developed by AITOPIA.<\/p>\n<p>We have seen this with \u201c<a href=\"https:\/\/cybersecuritynews.com\/malicious-chrome-extension-steal-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chat GPT for Chrome with GPT-5, Claude Sonnet &amp; DeepSeek AI<\/a>\u201d using the extension ID fnmihdojmnkclgjpcoonokmkhjpjechg.<\/p>\n<p>\u201cAI Sidebar with Deepseek, ChatGPT, Claude, and more\u201d operating under the ID inhcgfpbfdjbjogdfjbclgolkmhnooop. And \u201cTalk to ChatGPT\u201d utilizing the ID hoinfgbmegalflaolhknkdaajeafpilo.<\/p>\n<p>The second method involves compromising an established tool with a wide user base.<\/p>\n<p>A notable example is <a href=\"https:\/\/cybersecuritynews.com\/popular-chrome-extension-with-over-6-million-installs\/\" target=\"_blank\" rel=\"noreferrer noopener\">Urban VPN Proxy,<\/a> tracked under the extension ID eppiocemhmnlbhjplcgkofciiegomcon, which operated as a legitimate service for some time.<\/p>\n<p><a href=\"https:\/\/expel.com\/blog\/on-the-radar-chatgpt-stealer\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to Expel research<\/a>, once a large enough audience was established, the developers silently introduced prompt poaching capabilities in a subsequent update, immediately exposing all existing users to data exfiltration.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-organizational-risks-and-impact\"><strong>Organizational Risks and Impact<\/strong><\/h2>\n<p>The exfiltration of AI prompts presents severe risks to corporate security and personal privacy.<\/p>\n<p>Employees frequently rely on <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-servicenow-ai-assistants\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI assistants to draft strategic emails<\/a>, summarize proprietary documents, or debug internal code, inadvertently feeding highly sensitive data directly into these tools.<\/p>\n<p>When prompt poaching occurs, it exposes intellectual property, confidential customer data, and proprietary business logic.<\/p>\n<p>This stolen information can easily fuel <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">targeted<a href=\"https:\/\/cybersecuritynews.com\/malicious-svgs-in-phishing-campaigns-how-to-detect-hidden-redirects-and-payloads\/\" target=\"_blank\" rel=\"noopener\">\u00a0phishing<\/a><\/span><a href=\"https:\/\/cybersecuritynews.com\/malicious-svgs-in-phishing-campaigns-how-to-detect-hidden-redirects-and-payloads\/\" target=\"_blank\" rel=\"noreferrer noopener\"> campaigns, facilitate identity theft<\/a>, or end up brokered on underground hacker forums.<\/p>\n<p>To combat the threat of prompt poaching, organizations must <a href=\"https:\/\/cybersecuritynews.com\/8-best-browser-and-web-execution-security-platforms-for-2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">adopt strict browser management policies<\/a> rather than relying on user discretion.<\/p>\n<p>Security teams should proactively restrict unapproved plugins using Group Policy and centralized browser management consoles.<\/p>\n<p>Furthermore, organizations should address internal productivity gaps by steering employees toward official desktop clients or first-party extensions developed directly by trusted AI vendors.<\/p>\n<p>Finally, conducting periodic audits of installed extensions and monitoring network traffic for anomalous outbound connections can help identify and neutralize these stealthy threats before significant data loss occurs.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/prompt-poaching-attack\/\">New \u201cPrompt Poaching\u201d Attack Steals Users\u2019 AI Conversations via Malicious Browser Extensions<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/prompt-poaching-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New \u201cPrompt Poaching\u201d Attack Steals Users\u2019 AI Conversations via Malicious Browser Extensions For many users, engaging with an AI assistant requires opening a dedicated browser tab, which inherently isolates the AI from other browsing activities. While this separation improves privacy, it reduces usefulness and context. To bridge this gap, AI-powered browser extensions have surged in [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[167,657,129,63],"tags":[130],"class_list":["post-11709","post","type-post","status-publish","format-standard","hentry","category-ai","category-browser","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11709"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11709"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11709\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11709"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11709"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11709"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}