AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload
Malware Activity
Summary
Hide ▲
Show ▼
The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every update and uninstall, creating repeated browser-tab redirection for users. The poisoned code landed in versions 1.7.2.0 and 1.7.3.0 through Google's CRX content delivery network on July 31, 2026. The same release also suppresses DeepSeek redirection to ChatGPT, showing a deliberate change in extension behavior.
Related Happenings
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
H score30
First: 04.08.2026 22:03
Last: 04.08.2026 22:03
Sources 1
About this happening:
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware ActivityAbout this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users
Malware Activity
H score37
First: 03.08.2026 21:43
Last: 03.08.2026 21:43
Sources 1
About this happening:
Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-...
Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users
Malware ActivityAbout this happening: Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-...
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
JetBrains Marketplace malicious plugin API-key theft campaign
Campaign
H score15
First: 17.06.2026 00:54
Last: 17.06.2026 00:54
Sources 1
About this happening:
A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...
JetBrains Marketplace malicious plugin API-key theft campaign
CampaignAbout this happening: A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants*...
Miasma software supply chain campaign expands to new PyPI wave
Campaign
H score29
First: 09.06.2026 19:34
Last: 09.06.2026 19:34
Sources 1
About this happening:
The Miasma supply-chain campaign has expanded into a new PyPI wave, increasing the risk that developers and downstream users will ingest information-stealing malware t...
Miasma software supply chain campaign expands to new PyPI wave
CampaignAbout this happening: The Miasma supply-chain campaign has expanded into a new PyPI wave, increasing the risk that developers and downstream users will ingest information-stealing malware t...
Timeline
-
12.08.2026 17:09 2 articles · 2h ago
AI Sidebar update adds affiliate-link monetization payload
Technical Analysis UpdateGoogle's CRX content delivery network pushed versions 1.7.2.0 and 1.7.3.0 of AI Sidebar with Deepseek, ChatGPT, Claude, and more on July 31, 2026, adding a 21-line monetization payload that opens an affiliate link in a foreground browser tab on every update and uninstall and suppresses DeepSeek redirection to ChatGPT.
Show sources
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — thehackernews.com — 12.08.2026 17:09
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — thehackernews.com — 12.08.2026 17:09
-
12.08.2026 17:09 1 articles · 2h ago
Netskope flags AI Sidebar's return with a monetization payload
Initial DisclosureNetskope Threat Labs reported on August 12, 2026 that AI Sidebar with Deepseek, ChatGPT, Claude, and more had returned after earlier removal for Prompt Poaching tactics, and described a clean-then-poisoned update sequence that reintroduced a monetization payload tied to extension update and uninstall events.
Show sources
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — thehackernews.com — 12.08.2026 17:09