ChatGPT Plugin Marketplace Scam: Unreviewed 'Official' Plugins Steal Chat Records and API Keys
The main victim groups include two types. One is ordinary users who want to improve work efficiency through ChatGPT plugins. They often lack awareness of plugin permission boundaries and are easily induced by phrases such as 'official' and 'OpenAI certified' to paste API keys, internal company materials, or personal privacy into conversations. The other is independent developers and small technical teams. To quickly integrate into the ChatGPT ecosystem, they proactively search for and install plugins related to their business, but overlook source review and code auditing. The common psychological weakness of these victims is excessive trust in the security endorsement of major platforms, as well as abandoning the principle of least privilege in the face of high convenience. Many harbor the wishful thinking that 'things in the official marketplace can't have major problems.'
Key Fields
FIELD STAMPSWho Gets Targeted
The main victim groups include two types. One is ordinary users who want to improve work efficiency through ChatGPT plugins. They often lack awareness of plugin permission boundaries and are easily induced by phrases such as 'official' and 'OpenAI certified' to paste API keys, internal company materials, or personal privacy into conversations. The other is independent developers and small technical teams. To quickly integrate into the ChatGPT ecosystem, they proactively search for and install plugins related to their business, but overlook source review and code auditing. The common psychological weakness of these victims is excessive trust in the security endorsement of major platforms, as well as abandoning the principle of least privilege in the face of high convenience. Many harbor the wishful thinking that 'things in the official marketplace can't have major problems.'
骗局怎么运作
- Fake identity and packaging: Scammers register developer accounts with names that sound similar to official or well-known developers, use names such as 'ChatGPT Official Assistant' and 'OpenAI Certified Plugin,' and fabricate download counts, ratings, and user reviews in the description to create the illusion of having been reviewed.
- Listing unreviewed plugins or bypassing review: They exploit time gaps in the plugin marketplace review process, automated review vulnerabilities, or temporarily relaxed policies to submit plugins containing malicious scripts. Some plugins even evade checks by first submitting a normal version and then implanting malicious code through a later hot update.
- Inducing users to grant excessive permissions: In the plugin installation guidance, wording such as 'To help you automatically organize chat records, we need access to your full chat history and API call permissions' or 'Please paste your OpenAI API key to enable advanced features' leads users to voluntarily hand over sensitive permissions without understanding the consequences.
- Stealing chat records and keys: The malicious plugin sends all content users paste in conversations, API keys, access tokens, and even browser session information in the background to a server controlled by the attacker. The data is usually packaged and transmitted through encrypted channels to avoid detection by security tools.
- Monetization and secondary use: Attackers sell stolen API keys on the dark web or in key-trading groups, or directly use the stolen keys to call GPT interfaces for mining, bulk content generation, or phishing attacks; chat records may be used for targeted fraud, corporate intelligence gathering, or extortion.
红旗信号(看到这些快跑)
- 🚩 The plugin name or description contains words such as 'official,' 'certified,' or '100% safe,' but the developer account is not an official OpenAI account or a well-known vendor.
- 🚩 During installation, it requests access to full chat history or session tokens, or asks users to paste API keys, whereas normal plugins usually only require the minimum necessary permissions.
- 🚩 The plugin page shows abnormally high download counts or five-star reviews, but the review content is generic and templated and cannot be verified through public channels.
- 🚩 The developer account was registered recently, has few historical plugins, or is inconsistent with the company information in the plugin description.
- 🚩 After installation, abnormal network requests appear, or the plugin remains active in the background even when the user is not actively using it.
真实案例
- In June 2026, 15 malicious AI plugins were discovered on JetBrains Marketplace. They disguised themselves as normal coding assistants and stole AI API keys from about 70,000 developers. The incident was publicly reported by security media, and the attackers used the keys to call paid AI services for profit.
- In 2026, multiple Chrome extensions disguised as ChatGPT-related features were exposed, including names such as 'ChatGPT for Chrome with GPT-5.' They stole session tokens and API keys from a large number of users, with user scale ranging from 90,000 to 1.5 million. Some incidents were reported by Chinese technology media.
- Security researchers found during testing that multiple ChatGPT plugins had cross-account data leakage vulnerabilities. Attackers could read other users' data through hidden channels, and some vulnerabilities also involved unauthorized access to external services such as Gmail, showing that permission isolation flaws are widespread in the plugin ecosystem.
- In June 2026, security researchers disclosed 15 malicious AI plugins on JetBrains Marketplace: they disguised themselves as popular AI coding assistants such as DeepSeek and CodeGPT, induced users to enter API keys for services such as OpenAI, and transmitted them to overseas servers; among them, CodeGPT AI Assistant and DeepSeek AI Assist were each downloaded more than 25,000 times. (Source: https://beeble.com/zh/blog/15ge-xu-jiaai-cha-jian-ru-he-jiangjetbrains-shi-chang-bian-cheng-ping-ju-zi-zhu-can)
- In September 2026, security researchers disclosed a ChatGPT sandbox cross-account data leakage vulnerability: a hidden channel inside the ChatGPT code execution container could allow attackers to hijack victim sessions and silently steal data from connected applications such as Gmail; two Chrome extensions named at the same time that captured private AI chat conversations (Smart Adblocker, etc.) also had unauthorized access issues. (Source: https://cybersecuritynews.com/chatgpt-sandbox-gmail-data/)
Official Stance
- In 2026, the National Internet Emergency Center (CNCERT), in an AI supply chain security bulletin, warned that credential theft attacks against AI plugins and extensions are on the rise, and recommended that developers and users strengthen permission review.
- In 2026, CCTV Finance Channel, in a program about AI security, reminded the public not to readily trust third-party AI plugins bearing words such as 'official certification,' and to verify the developer's identity and permission requests before installation.
- In 2026, multiple international cybersecurity agencies issued advisories stating that malicious ChatGPT plugins and extensions are spreading through official marketplace channels, and recommended that enterprise IAM teams monitor anomalous token usage.
How to Protect Yourself
- ✅ Before installing any ChatGPT plugin, check the developer account's registration date, historical plugins, and other user reviews, and cross-verify through search engines for negative records.
- ✅ Refuse any plugin that asks users to paste API keys, access full chat records, or read session tokens, and adhere to the principle of least privilege.
- ✅ Outside the official plugin marketplace, do not casually download so-called 'official plugin installers' from forums, cloud drives, or third parties.
- ✅ Regularly check active applications and token usage records in the account. If abnormal IPs or calls are found, immediately revoke the relevant keys and change passwords.
- ✅ Enterprise users should use IAM tools to set usage scope, quota limits, and expiration times for API keys to reduce losses after a single key is leaked.