Friday, September 11, 2026

PromptSnatcher Browser Extensions Abuse AI Platforms to Capture Full Chat Conversations

PromptSnatcher (internal identifier: Panel 231) is a modern, stealthy data collection operation embedded inside two browser extensions that masquerade as ad‑blockers while harvesting full chat conversations and account metadata from major AI platforms.

The extensions deliver genuine ad‑blocking and cookie‑banner suppression by ingesting legitimate public filter lists such as EasyList and I Don’t Care About Cookies, but they also ship a bespoke interception engine that captures non‑public conversation text, model identifiers, and subscription‑tier signals from ChatGPT, Gemini, Claude, Copilot, Perplexity, Grok, DeepSeek and Meta AI.

The campaign demonstrates clear, modular design, remote configurability, and deliberate attempts to conceal telemetry inside legitimate functionality.

The discovery began when the MalExt Sentry automated scanner flagged a recurring Google Tag Manager ID (GTM‑TCT2RJ) across multiple extensions’ filter rules.

That GTM artifact traced back to a rule in the IDCAC list and proved non‑attributive, but it provided a forensic pivot for manual review.

Deeper static and dynamic analysis revealed the true linkage: a shared “Panel 231” SDK present in both extensions.

The SDK contains identical obfuscated exfiltration logic, a common LDP_MESSAGE internal messaging protocol, and matching command‑and‑control (C2) behavior patterns across distinct publisher domains.

The investigation was initially flagged by the MalExt Sentry automated scanner due to a recurrence of the Google Tag Manager ID GTM-TCT2RJ across multiple extensions’ filter rules.

Forensics show an original, professional background manager rather than borrowed privacy‑extension code.

PromptSnatcher Browser Extensions Abuse AI

The engine implements a user onboarding “Enhanced Protection” flow that does not specify AI conversation capture and fetches platform‑specific parsing logic at runtime from a /configuration endpoint.

This dynamic payload approach allows the operator to add or modify parsing rules and activate new targets without pushing extension updates to the browser stores.

In practice, the extension injects a capture script into the page main world that patches global fetch, XMLHttpRequest, and WebSocket constructors to clone outgoing and incoming traffic in real time.

Captured content is buffered and relayed through the LDP_MESSAGE channel to the background worker, then POSTed to a /captures API with a persistent per‑install UUID, platform ID, conversation ID, model name, subscription tier and timestamp.

The remote configuration (Config v1.0.1) exposes the campaign’s scope and sophistication. Targets include ChatGPT (fetch scraping window._STATSIG_ to obtain is_paid), Gemini (XHR parsing for a wrb‑frames protocol), Claude (probing /api/organizations for capabilities), Copilot (intercepting SignalR frames over WebSocket and probing Pro tier), Perplexity (scraping subscription_status), Grok and DeepSeek via backend APIs, and Meta AI via GraphQL variables.

Notably Meta AI is absent from static manifests but present in the live remote config, underlining the operator’s ability to enable new platforms on demand.

The capture payloads are sizable (buffers configured for tens of thousands of characters) to ensure full prompts and responses are retained.

Infrastructure is segmented: Extension A calls c.smartadblocker.com while Extension B calls c.abforbrowser.com. The /configuration endpoint returns a Base64‑encoded parser ruleset and validates requests via an Origin header tied to the extension ID, limiting casual probing.

Despite this operational discipline, a material disclosure discrepancy exists: the Firefox variants declare data_collection_permissions: none in their manifests, yet they exhibit the same capture behavior as the Chrome builds.

PromptSnatcher is deployed to roughly 90,000 users, making it one of the more consequential client‑side data exfiltration campaigns targeting AI conversations.

Defenders should prioritize removing the affected extensions, block the listed C2 domains at network perimeter, and audit any sensitive prompts or responses potentially exposed.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News