Find notable cyber news and cases, enriched with sources, timelines, and signals.

AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload

Malware Activity
First reported
Last updated
Happening score
H score 11
1 unique sources, 1 articles

Summary

Hide ▲

The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every update and uninstall, creating repeated browser-tab redirection for users. The poisoned code landed in versions 1.7.2.0 and 1.7.3.0 through Google's CRX content delivery network on July 31, 2026. The same release also suppresses DeepSeek redirection to ChatGPT, showing a deliberate change in extension behavior.

Related Happenings

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
H score30 First: 04.08.2026 22:03 Last: 04.08.2026 22:03 Sources 1

About this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...

Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users

Malware Activity
H score37 First: 03.08.2026 21:43 Last: 03.08.2026 21:43 Sources 1

About this happening: Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-...

StegoAd malicious Edge extension operation

Malware Activity
H score19 First: 29.06.2026 11:32 Last: 29.06.2026 11:32 Sources 1

About this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...

JetBrains Marketplace malicious plugin API-key theft campaign

Campaign
H score15 First: 17.06.2026 00:54 Last: 17.06.2026 00:54 Sources 1

About this happening: A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...

Miasma software supply chain campaign expands to new PyPI wave

Campaign
H score29 First: 09.06.2026 19:34 Last: 09.06.2026 19:34 Sources 1

About this happening: The Miasma supply-chain campaign has expanded into a new PyPI wave, increasing the risk that developers and downstream users will ingest information-stealing malware t...

Timeline

  1. 12.08.2026 17:09 2 articles · 2h ago

    AI Sidebar update adds affiliate-link monetization payload

    Technical Analysis Update

    Google's CRX content delivery network pushed versions 1.7.2.0 and 1.7.3.0 of AI Sidebar with Deepseek, ChatGPT, Claude, and more on July 31, 2026, adding a 21-line monetization payload that opens an affiliate link in a foreground browser tab on every update and uninstall and suppresses DeepSeek redirection to ChatGPT.

    Show sources
  2. 12.08.2026 17:09 1 articles · 2h ago

    Netskope flags AI Sidebar's return with a monetization payload

    Initial Disclosure

    Netskope Threat Labs reported on August 12, 2026 that AI Sidebar with Deepseek, ChatGPT, Claude, and more had returned after earlier removal for Prompt Poaching tactics, and described a clean-then-poisoned update sequence that reintroduced a monetization payload tied to extension update and uninstall events.

    Show sources