Banned chat-scraping extension returns, opens affiliate links
A Chrome extension pulled in January 2026 for scraping ChatGPT and DeepSeek chats has returned to the Chrome Web Store and now opens affiliate links on updates and hijacks uninstall URLs, Netskope reported.
A Chrome extension removed in January 2026 for scraping conversations from ChatGPT and DeepSeek is back on the Chrome Web Store and is delivering update-based affiliate links and an uninstall hijack, Netskope Threat Labs reported.
The extension, listed as “AI Sidebar with DeepSeek, ChatGPT, Claude and more,” was first flagged in December 2025 for sending chat content to external domains. Google removed the add-on in January 2026 after it had more than 300,000 installs and a 4.6-star rating. Later builds removed the scraping code and the extension’s privacy policy references the earlier conduct.
Netskope observed the extension active again in August 2026 and traced updates to enterprise endpoints through Google’s CRX distribution. Version 1.7.2.0, pushed between July 20 and 31, 2026, appeared to contain only benign features. About two weeks later, version 1.7.3.0 added a 21-line change to a single script that introduced a monetization mechanism.
In Netskope’s analysis, the extension’s service worker opens a foreground tab when Chrome reports an update. That tab follows an affiliate link routed through a URL shortener to an AI video-generation platform that operates a public affiliate program. The code triggers on updates rather than installs, which allows each new release to generate a referral event.
The extension also overwrites the registered uninstall URL five seconds after it loads. Chrome executes only the most recently registered uninstall endpoint, so the overwrite causes removals to trigger the affiliate referral URL.
Files packaged with the extension name Extchange.com as developer and data controller; that domain was registered in February 2024 and lists no public registrant. The Chrome Web Store listing shows the developer as DeepSeek AI, which does not match the packaged files. Netskope classified build 1.7.3.0 as Trojan.GenericFCA.Script.37952 and reported blocking that version at enterprise endpoints via Google’s CDN.
Netskope reported the behavior to the Chrome Web Store and recommended that organizations remove the add-on from managed browsers. The firm described the affiliate changes as lower impact than the earlier data-exfiltration behavior and noted the same update channel can deliver different code in future releases.








