Chrome extension disguised as AI assistant expose 10K+ users OpenAI API keys
A Chrome extension named H-Chat Assistant, disguised as an AI assistant, has compromised over 10,000 users' OpenAI API keys, sending them to third-party servers. Identified by Obsidian Security, the extension initially functioned as advertised but secretly harvested user data. The malicious activity began in July 2024, unnoticed until January 2025, when OpenAI revoked the compromised keys. Despite the discovery, the extension remained available on the Chrome Web Store. Researchers warn that similar malicious extensions could exploit users due to the popularity of AI tools.
Cryptopolitan·