Browser extension AI chat exfiltration
Browser extension AI chat exfiltration is the practice of browser extensions, primarily distributed through the Chrome Web Store, reading the content of users' conversations with AI chatbots such as ChatGPT, Claude, Character.AI and DeepSeek, typically along with the user's full URL history, shipping that data to remote servers controlled by the extension's publisher or its parent data-broker company. A 11 May 2026 investigation by security researcher James Arnott of amibeingpwned.com identified seven Chrome extensions with a combined install base of more than seven million users that were either actively exfiltrating AI chat content or carried the server-controlled infrastructure to begin doing so on command; most of the seven carried Google's Featured or Verified badges at the time of disclosure.[1] The pattern follows a December 2025 disclosure by Koi Security that the Urban VPN Proxy extension, with more than seven million users across Chrome and Edge, had been logging conversations with eight separate AI assistants since a 9 July 2025 update,[2] and a January 2026 OX Security disclosure of two ChatGPT-impersonating extensions with a combined 900,000 users that posted users' chats to attacker-controlled servers every 30 minutes.[3]
Background
[edit | edit source]A browser extension is a small program a user installs onto their web browser to add features such as ad-blocking, changing how a site looks, or giving the user more information about a site they are using. Once installed, extensions can run scripts in every web page the user accesses. If the extension was given the read-your-browsing-history permission or the broader permission to read and modify any web page, it can see every URL the user visits and it can read the text of any page the browser displays, including a user's typed prompts to an AI chatbot and the chatbot's replies.
Technically, the read-the-page capability is typically delivered through a content script: a piece of extension code injected into the page that can read the rendered HTML directly. Because the content script runs inside the browser after the TLS connection to ChatGPT or Claude has already been decrypted, the encryption between the user and the AI provider does not protect the chat from the extension. A separate background service worker in the extension can take what the content script reads and post it to a remote server the publisher controls.[4] Google's own Chrome Web Store Limited Use policy states that "Collection and use of web browsing activity is prohibited, except to the extent required for a user-facing feature described prominently in the Product's Chrome Web Store page and in the Product's user interface."[5] The cases below indicate that this policy is not consistently enforced.
The May 2026 amibeingpwned.com investigation
[edit | edit source]On 11 May 2026, James Arnott published The AI Chat Scraping Extension Wall of Shame on amibeingpwned.com, a project of Bay Area Labs Inc. Arnott's methodology combined static and dynamic analysis in the AIBP sandbox with manual packet capture; for each Confirmed entry, he watched the AI chat content leave the browser in network traffic in his own sand-boxed browser and decoded the obfuscated payloads before classification.[1] Arnott divided his findings into two categories: Confirmed, meaning he observed chat content leaving the browser during testing, and Capability, meaning the exfiltration code path and remote endpoint were present and wired up but did not fire in the observation window, which he attributed to server-side gating through remote configuration.[1]
Arnott explained the Capability category as follows:
Remote config lets an extension fetch instructions from a server at runtime, changing behaviour after install without an update. It's also a convenient way to dodge sandbox detection, which is what we think we're looking at in the Capability entries below.[1]
The seven extensions Arnott named, with the install counts, owner attributions, status and obfuscation type he documented, are summarised below.[1]
| Extension | Users | Owner | Status | Obfuscation |
|---|---|---|---|---|
| Stylish | 2,000,000 | SimilarWeb | Confirmed | Extensive (five-stage chain) |
| Poper Blocker | 2,000,000 | Big Star Labs LP | Confirmed | Character mapping |
| SimilarWeb | 1,000,000 | SimilarWeb | Confirmed | None |
| StayFocusd | 700,000 | SensorTower | Capability | LZ-String |
| CrxMouse | 700,000 | Big Star Labs LP | Capability | Base64 |
| WhatRuns | 400,000 | Owned it Ltd | Confirmed | None |
| StayFree | 200,000 | SensorTower | Capability | LZ-String |
Arnott separately listed the Urban VPN Proxy extension, with more than eight million users, as an "honourable mention" because it had been caught and had ceased AI-chat scraping after the December 2025 Koi Security disclosure, although it continued to exfiltrate URLs with LZ-String compression at the time of his post.[1] Arnott also published primary video evidence of two of the Confirmed entries on the amibeingpwned YouTube channel, demonstrating WhatRuns exfiltration[6] and the StayFocusd infrastructure analysis.[7]
How the exfiltration works
[edit | edit source]For a non-technical reader: the Stylish extension wraps every URL the user visits in five layers of encoding before sending it to its servers, which makes it harder for a casual reviewer or an automated Chrome Web Store check to see what is being sent. The encoded request leaves the browser every time the user opens a new page, whether or not the user is doing anything with the extension at that moment.[4]
Arnott reverse-engineered the Stylish payload and published the structure in a 26 February 2026 post. The JSON payload the extension builds in its background service worker contains, among other fields, gp (the current URL), klm (the previous URL) and pxe (a unique identifier for the user).[4] The sample payload Arnott captured from a single page visit reads:[4]
{
"gp": "https://userstylesapi.com/top/styles",
"klm": "https://www.google.com/search?q=test+google&rlz=1C5OZZY_enGB1156GB1156&oq=test&gs_lcrp=Eg...",
"ver": "https://www.google.com/search?q=test+google&rlz=1C5OZZY_enGB1156GB1156&oq=test&gs_lcrp=Eg...",
"knl": "",
"dig": "2008511158",
"tmg": "link",
"trp": "exthead",
"st": "1772053130391",
"ch": "9",
"di": "a3e3e2a81",
"pxe": "Lk85G2SeiETEPNOWlrR15mLsZDsC",
"vmt": "6",
"lav": "21",
"wv": "1",
"gr": "3.4.10",
"craz": "AAEAAAAAAG0RCwIRdAAAAAAAAAAAAAAAAAAAAAAAAAA="
}
Arnott documented the obfuscation chain applied to that payload before it is posted:
URL encoding to a query string ... Double base64 encoded JSON stringified, then base64 again ... Columnar transposition cipher, the base64 string is split into 48-character rows, then read column-by-column instead of row-by-row, scrambling the text ... AES-256-CBC encrypted using a symmetric key hardcoded in the extension source code ... Base64 encoded one final time.[4]
Arnott observed that the AES-256-CBC step uses a symmetric key compiled into the extension's source code, which means anyone willing to read the extension's JavaScript can decrypt the traffic; he published a working JavaScript decoder using the recovered key.[4] His commentary on the design choice was direct:
I do like the use of a hardcoded encryption key as it makes my life so much easier, although I do wonder if they've heard of this revolutionary "asymmetric encryption" where they can avoid having this hardcoded key for encryption and decryption.[4]
Other extensions in Arnott's list applied lighter obfuscation or none at all. Poper Blocker used a character-mapping scheme; CrxMouse used base64; StayFocusd and StayFree used the LZ-String library, which Arnott characterised as compression; WhatRuns and the SimilarWeb extension applied no obfuscation to the exfiltrated requests at all.[1] WhatRuns, in Arnott's words, "exfiltrates every URL you visit, alongside AI chats. No exceptions here, they don't even bother to obfuscate the requests."[1]
The Capability extensions are gated server-side, which is why a one-shot sandbox check does not see them firing. Arnott documented the Poper Blocker case in detail: the AI-chat scraping code path and endpoint were present, but the exfiltration only began after the sandbox's user identifier had aged for roughly a day. In his words: "We initially did not see AI chat scraping in our sandbox, but after leaving the user ID to age for a day, the scraping kicked in, confirming the server-side timer gated on user-ID age."[1] Arnott documented StayFocusd's behaviour as the same pattern with a different trigger: the AI-chat scraping path was present behind a remote configuration flag that was off in initial testing and was not observed to be on at any point during testing, however Arnott demonstrated the capability of StayFocusd's scraping by swapping out the remote server for a locally controlled one which confirmed the AI-chat scraping capability could be remotely enabled.[1] The category covers ChatGPT, Claude and Character.AI; Arnott names those three providers as the targets exfiltrated by Stylish.[1]
Owning companies
[edit | edit source]SimilarWeb
[edit | edit source]SimilarWeb is the publisher of both the Stylish extension and an extension named after the company itself. Arnott documented both as Confirmed AI-chat exfiltrators, with the SimilarWeb-branded extension sending AI chats and full URLs even when the user is not interacting with it.[1] Stylish has carried SimilarWeb's name as publisher since the company acquired the extension in January 2017; Robert Heaton documented in July 2018 that the post-acquisition version recorded every URL Stylish's two million users visited and sent those URLs to SimilarWeb's servers with a unique identifier.[8] Arnott separately observed a contradiction between the Stylish privacy policy, which he says explicitly states the company sells personal data, and the Chrome Web Store listing's larger-font claim on the home page that it does not.[4] As of May 2026 the Stylish Chrome Web Store listing names "Similarweb LTD" as the publisher, reports two million users and shows the Featured badge.[9] It should be noted that SimilarWeb offers on their website Data-as-a-Service, allowing businesses to "Harness billions of data points from across the digital landscape to fuel business growth with Similarweb's Data-as-a-Service."[10]
Sensor Tower
[edit | edit source]Sensor Tower is the publisher of StayFocusd and StayFree, both classified by Arnott as Capability for AI-chat exfiltration and both observed exfiltrating most URLs the user visits, with a US-centric whitelist for adult sites, US health sites and regex filters for US Social Security numbers and ZIP codes that does not protect users in other countries.[1] StayFocusd's Chrome Web Store listing as of May 2026 names "Sensor Tower" as publisher, reports 700,000 users, shows the Featured badge & describes "Gen AI Analytics: Track and analyze your usage of AI chat platforms directly from the StayFocusd" as a feature while separately stating "StayFocusd does not collect personal data from the web pages you visit."[11]
Big Star Labs LP
[edit | edit source]Big Star Labs LP is the publisher of Poper Blocker & CrxMouse. Arnott observed Poper Blocker exfiltrating URLS[12] with character-mapping obfuscation and gated AI-chat scraping that activated after a 24-hour user-ID age, and observed CrxMouse exfiltrating URLs with base64 obfuscation and carrying the same remote-config infrastructure, however Arnott did not observe CrxMouse explicitly exfiltrating AI-chats during the period of testing.[1] A name match exists with a 2018 AdGuard investigation by Andrey Meshkov, which documented a Delaware-registered "Big Star Labs" entity whose Chrome extensions and mobile apps were collecting browsing histories from more than 11 million users; AdGuard noted that "Every document that contains the company name is an image (in other words, you cannot simply Google their name), they use different accounts in extension stores, and the domain owners aren't publicized."[13] Whether the 2026 "Big Star Labs LP" is the same legal entity is not established in cited sources; only the name match is.
Owned it Ltd
[edit | edit source]Owned it Ltd is the publisher of WhatRuns, which Arnott documented as Confirmed for AI-chat exfiltration with no obfuscation applied to the outbound requests.[1] The Chrome Web Store listing for WhatRuns as of May 2026 names "Ownedit Ltd" as the publisher, reports 400,000 users, shows the Featured badge and lists a developer address at 11 Brindley Place, Birmingham B1 2LP, United Kingdom.[14]
Historical precedent
[edit | edit source]Stylish was an open-source browser extension before SimilarWeb acquired it in January 2017. Robert Heaton's 2 July 2018 disclosure documented that the post-acquisition Stylish recorded every URL its users visited and sent that history to SimilarWeb together with a unique identifier; for users who had created a userstyles.org account, that identifier could be linked to a login cookie and through it to a real identity.[8] Heaton found the exfiltrated payloads in Burp Suite as "a large number of strange-looking requests going to api.userstyles.org" carrying base64-encoded blobs.[8] Heaton's post updated to note that "2 days after publication of this post, Stylish was removed from the Chrome and Firefox stores. 3 weeks later, a new version is back in the Firefox store."[8] Arnott's February 2026 follow-up confirms that Stylish has returned to the Chrome Web Store carrying the Featured badge and is again exfiltrating the same categories of data.[4] The community-maintained open-source fork of the original Stylish codebase, named Stylus, has roughly 900,000 users, does not phone home and caches styles on the user's local machine; Arnott recommends it as the direct replacement.[4]
Related contemporaneous cases
[edit | edit source]Urban VPN Proxy
[edit | edit source]In December 2025, Koi Security disclosed that Urban VPN Proxy, a Chrome and Edge extension with more than seven million users, had been logging users' conversations with eight AI assistants since a 9 July 2025 version 5.5.0 update; the platforms intercepted were ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, DeepSeek, Grok (xAI) & Meta AI.[2] Malwarebytes Labs corroborated the finding and noted that the extension sat in the Chrome Web Store with a 4.7-star rating and Google's Featured badge.[2] The captured conversations were forwarded to Urban Cybersecurity's parent company, BiScience (B.I Science (2009) Ltd), which Malwarebytes characterised as a data broker collecting browsing history and device identifiers from millions of users.[2] Malwarebytes reported that as of the date of its post, "Urban Proxy VPN and Urban Cybersecurity's other apps appeared to have been removed from the Chrome Web Store."[2]
AITOPIA-impersonating extensions
[edit | edit source]On 30 December 2025, OX Security researcher Moshe Siman Tov Bustan disclosed two extensions impersonating the legitimate AITOPIA extension with a combined 900,000 users. The two extensions, Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI and AI Sidebar with Deepseek, ChatGPT, Claude and more, were "found exfiltrating user conversations and all Chrome tab URLs to a remote C2 server every 30 minutes."[15] One of the two, the ChatGPT-named extension with more than 600,000 users, carried Google's Featured badge at the time of the disclosure.[15] Ravie Lakshmanan of The Hacker News reported on 6 January 2026 that the extensions were still available for download as of writing but that the ChatGPT-named one "has since been stripped of its 'Featured' badge."[3] The Hacker News also reported that John Tuckner of Secure Annex had coined the term "Prompt Poaching" for the broader pattern of using browser extensions to capture AI conversations covertly, and had separately identified the SimilarWeb extension and SensorTower's StayFocusd as legitimate analytics-company extensions engaged in the same conduct.[3] By 7 January 2026, SecurityWeek reported that both AITOPIA-impersonating extensions were no longer available in the Chrome Web Store.[16]
Chrome Web Store response and policy gap
[edit | edit source]Google introduced the Chrome Web Store Featured badge in April 2022, telling users that the badge marks extensions that "follow our technical best practices and meet a high standard of user experience and design" and that "Chrome team members manually evaluate each extension before it receives the badge."[17] Every extension in Arnott's May 2026 list carried Featured, Verified or both at the time of his post.[1] Arnott's published conclusion was that badges in practice correlate with public attention rather than with audited compliance. In the section The Chrome Web Store badge problem he wrote:
In our experience, Chrome only takes away badges when there's a public outcry. Which is why investigations like this matter.[1]
In the What can users do? section, he added:
Don't treat "Featured" or "Verified" as a safety signal. Every extension on this list has at least one.[1]
Arnott also documented a direct contradiction between the privacy disclosures of the Stylish extension and its Chrome Web Store listing. The Stylish privacy policy, per his reading, explicitly states the publisher sells personal data; the Chrome Web Store listing's larger-font homepage text states that the publisher does not sell personal data; & the Chrome Web Store's approved-use-cases policy itself prohibits the sale of user data.[4]
- Contradiction between the Stylish privacy policy and the Stylish Chrome Web Store listing.
-
Stylish (userstyles.org) privacy policy, section headed CATEGORIES OF PERSONAL INFORMATION THAT WE COLLECT, DISCLOSE, AND SELL, with the categories itemised in the table below. Verify at the source:[18]
-
Stylish Chrome Web Store listing, larger-font block headed This developer declares that your data is, first bullet Not being sold to third parties, outside of the approved use cases. Verify at the source:[19]
Consumer impact and mitigation
[edit | edit source]The data leaving the browser in these cases falls into three categories: the text of the user's AI chatbot conversations (the prompts the user typed and the chatbot's replies), the full URL of every page the user visits including search queries and any tokens embedded in URLs, and a persistent unique identifier that lets the receiving company link those records across sessions.[1][4] Heaton's 2018 analysis of the same data category at SimilarWeb gave the worked examples that still apply: single-use password-reset links, time-limited authentication tokens for medical records and Google search-result URLs are all captured because they live inside the URL the extension sees.[8] Arnott extends the harm analysis to AI chat content, with the worked example of a user typing search terms about something covered by a non-disclosure agreement or a corporate spear-phishing target list being built from a captured record of which web-based software a target uses.[4]
For non-technical users, the practical mitigations documented in the cited sources are: audit installed extensions and remove anything not actively used, since the permissions persist after install; do not treat the Chrome Web Store "Featured" or "Verified" badges as safety signals;[1] and for users of Stylish specifically, switch to the open-source fork Stylus, which caches styles locally on the user's machine and does not phone home.[4] For organisations, Tuckner's summary in The Hacker News is the operational frame: "It is clear prompt poaching has arrived to capture your most sensitive conversations and browser extensions are the exploit vector."[3]
See also
[edit | edit source]- Browser extension data harvesting
- Chrome Web Store
- Data broker
- Right to repair
- Sensor Tower
- SimilarWeb
References
[edit | edit source]- ↑ 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 1.10 1.11 1.12 1.13 1.14 1.15 1.16 1.17 1.18 1.19 Arnott, James (11 May 2026). "The AI Chat Scraping Extension Wall of Shame". Am I Being Pwned. Archived from the original on 1 Jun 2026. Retrieved 13 Sep 2026.
- ↑ 2.0 2.1 2.2 2.3 2.4 Bradbury, Danny (18 Dec 2025). "Chrome extension slurps up AI chats after users installed it for privacy". =Malwarebytes. Archived from the original on 18 Dec 2025. Retrieved 13 Sep 2026.
{{cite web}}: CS1 maint: extra punctuation (link) - ↑ 3.0 3.1 3.2 3.3 Lakshmanan, Ravie (6 Jan 2026). "Two Chrome Extensions Caught Stealing ChatGPT and DeepSeek Chats from 900,000 Users". The Hacker News. Archived from the original on 6 Jan 2026. Retrieved 13 Sep 2026.
- ↑ 4.00 4.01 4.02 4.03 4.04 4.05 4.06 4.07 4.08 4.09 4.10 4.11 4.12 4.13 Arnott, James (26 Feb 2026). "Stylish is Back, Back again!". Am I Being Pwned. Archived from the original on 1 Jun 2026. Retrieved 13 Sep 2026.
- ↑ "Limited Use". Chrome. 1 Nov 2022. Archived from the original on 19 Aug 2026. Retrieved 13 Sep 2026.
- ↑ amibeingpwned (18 Feb 2026). "WhatRuns caught scraping AI chats". YouTube. Archived from the original on 13 Sep 2026. Retrieved 13 Sep 2026.
- ↑ amibeingpwned (18 Feb 2026). "StayFocusd, is this productivity tool acting like Spyware?". YouTube. Archived from the original on 13 Sep 2026. Retrieved 13 Sep 2026.
- ↑ 8.0 8.1 8.2 8.3 8.4 Heaton, Robert (2 Jul 2018). "'Stylish' browser extension steals all your internet history". Robert Heaton. Archived from the original on 3 Jul 2018. Retrieved 13 Sep 2026.
- ↑ "Stylish - Custom themes for any website". Google. Archived from the original on 5 Aug 2026. Retrieved 13 Sep 2026.
- ↑ "SimilarWeb Data-as-a-Service Solutions". SimilarWeb. Archived from the original on 30 Aug 2026. Retrieved 13 Sep 2026.
- ↑ "StayFocusd - Website Blocker & Focus Timer & Shorts Blocker". Google. Archived from the original on 14 Sep 2026. Retrieved 13 Sep 2026.
- ↑ amibeingpwned (31 May 2026). "Poper Blocker URL + AI Chat Exfiltration". YouTube. Archived from the original on 13 Sep 2026. Retrieved 13 Sep 2026.
- ↑ Meshkov, Andrey (24 Jul 2018). "Big Star Labs Spyware Campaign". AdGuard. Archived from the original on 22 May 2019. Retrieved 13 Sep 2026.
- ↑ "WhatRuns". Google. Archived from the original on 24 Aug 2026. Retrieved 13 Sep 2026.
- ↑ 15.0 15.1 Siman Tov Bustan, Moshe (30 Dec 2025). "Malicious Chrome Extensions Steal ChatGPT Conversations". OX. Archived from the original on 14 Sep 2026. Retrieved 13 Sep 2026.
- ↑ Arghire, Ionut (7 Jan 2026). "Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats". SecurityWeek. Archived from the original on 7 Jan 2026. Retrieved 13 Sep 2026.
- ↑ Kim, Debbie (20 Apr 2022). "Find great extensions with new Chrome Web Store badges". Google. Archived from the original on 19 Aug 2026. Retrieved 13 Sep 2026.
- ↑ "Privacy Policy". userstyles.org. 16 Feb 2026. Archived from the original on 16 Feb 2026. Retrieved 31 May 2026.
- ↑ "Stylish - Custom themes for any website (privacy disclosure block)". Google. Archived from the original on 5 Aug 2026. Retrieved 31 May 2026.