A Chrome extension that was previously removed for stealing AI chat content is back in Google’s store and again delivering malicious behavior to users, including enterprise browsers. Netskope says 'AI Sidebar with DeepSeek, ChatGPT, Claude and more' pushed clean version 1.7.2.0 from July 20-31, 2026, then version 1.7.3.0 added code that abused Chrome update and uninstall events to open affiliate links; earlier reporting tied the same extension to scraping ChatGPT and DeepSeek conversations and sending them to external domains.
Why it matters: Anyone who installed this extension may be exposed to unwanted actions today and potentially more serious payloads in later updates because Google’s own extension update mechanism is being abused. Organizations should remove the extension, review browser-extension allowlists, and check managed Chrome environments for versions 1.7.2.0 and 1.7.3.0.
Eduard Kovacs
2026.08.11
100% relevant
This article establishes a distinct ongoing malicious extension case: the same Chrome extension previously removed over AI conversation theft has returned to the Chrome Web Store and is once again distributing harmful code via Google’s CRX update infrastructure.
← Back to all stories