The Chrome extension “AI Sidebar with DeepSeek AI” was relisted after being removed for stealing AI conversation content, and its latest build now performs affiliate referral fraud through silent tab opens on update and uninstall. Netskope found the malicious version 1.7.3.0 being delivered to enterprise endpoints via Google’s CRX distribution, with the extension ID inhcgfpbfdjbjogdfjbclgolkmhnooop and prior exfiltration domains deepaichats[.]com and chatsaigpt[.]com. #AISidebarwithDeepSeekAI #inhcgfpbfdjbjogdfjbclgolkmhnooop #deepaichats #chatsaigpt
Keypoints
- The Chrome extension “AI Sidebar with DeepSeek AI” was removed in January 2026 for stealing AI conversation data, then later relisted and updated again.
- Version 1.7.2.0 was a clean release used to establish a benign update history before the malicious payload was reintroduced in version 1.7.3.0.
- The new build no longer exfiltrates chat content, but it silently opens an affiliate link on every extension update and uninstall event.
- The affiliate-fraud behavior uses a foreground browser tab and a race condition around Chrome’s uninstall URL handling to claim referrals.
- Netskope observed the malicious .crx being delivered to enterprise endpoints through Google’s CRX content delivery infrastructure.
- The extension is associated with the ID inhcgfpbfdjbjogdfjbclgolkmhnooop, and the prior data-theft infrastructure used deepaichats[.]com and chatsaigpt[.]com.
- The publisher appears to be Extchange.com, with the package also referencing aitopia.ai and a contact address tied to deepseek[.]ai branding.
MITRE Techniques
- [T1204.001 ] User Execution: Malicious Link – The extension opens an affiliate URL in a foreground tab with no user interaction, effectively driving users to a crafted link (‘the `active: true` argument means that no user interaction is required’).
- [T1176 ] Browser Session Hijacking / Browser Extension Abuse – The extension’s malicious behavior is delivered through a Chrome extension that updates existing installs and manipulates browser behavior (‘the same extension ID, a new build’ and ‘still shipping code to enterprise browsers’).
- [T1105 ] Ingress Tool Transfer – The malicious .crx package is delivered to endpoints via Google’s CDN (‘detected and blocked the latest version 1.7.3.0 of the .crx object arriving on enterprise endpoints from Google CDN’).
- [T1036 ] Masquerading – The operator used a clean version before reintroducing the payload to make the release history appear trustworthy (‘Version 1.7.2.0 distributed no malicious payload’ and then ‘a clean release to build a trustworthy release history’).
- [T1556 ] Modify Authentication Process / Trust Relationship Abuse – The update and uninstall flow is abused to generate affiliate credit instead of legitimate behavior (‘opens it … whenever Chrome reports an update’ and ‘The uninstall path is claimed the same way’).
Indicators of Compromise
- [Chrome Extension ID ] malicious extension identifier used by the relisted build – inhcgfpbfdjbjogdfjbclgolkmhnooop
- [SHA-256 ] malicious and clean CRX package hashes – 2a57de8abd0d15e92784280e5d39906d69a2ae7bb9b2875c77c626e9f0794e05, d3e0045b4151b360fdc054c5a7a0364afb3d8aea12dfeb38f3374bb977a8c579
- [URL ] affiliate redirect opened on update and uninstall – https://bit[.]ly/3RPe03x
- [Domain ] prior conversation-exfiltration command-and-control / data collection endpoints – deepaichats[.]com, chatsaigpt[.]com
- [Email Address ] operator and privacy contacts referenced in the package and listing – info@extchange[.]com, info@deepseek[.]ai
Read more: https://www.netskope.com/blog/ai-sidebar-extension-monetizes-its-own-updates