The evidence is narrower than “confirmed spyware campaign.” Bay Area Labs alleges, via Dark Reading, that Poper Blocker collected complete page URLs and ChatGPT, Claude, and Gemini conversations—including prompts, responses, titles, model and subscription information. Secondary reports add screenshots, location and cross-device identifiers, plus obfuscation and sandbox detection. Google was reportedly notified in May 2026, but the available reporting does not establish the first malicious version, first collection date, exfiltration destinations, session-cookie theft, or independent confirmation from Google. Do not invent a clean version cutoff.
Today, inventory by extension ID bkkbcggnhapdmkeljlodobbkopceiche, not display name. Query managed-browser inventories and endpoint extension directories for every Chrome profile; record user, device, installed version, installation source, first/last-seen time and update time. Because the malicious-version boundary is unknown, define each endpoint’s potential exposure window as earliest retained evidence of installation through verified removal. May 2026 is a useful investigation pivot because that is when Google was reportedly notified—not a safe-before date. Preserve the extension package and relevant browser, proxy and DNS records from a small representative set, then block the ID enterprise-wide, force removal and browser restart, and verify absence. Evidence collection must not delay containment.
For every affected profile, correlate that window with proxy/CASB logs and browser history to identify visits to ChatGPT, Claude, Gemini, email, identity portals, cloud consoles, source repositories and financial systems. Treat AI prompts and responses during that overlap as potentially disclosed; review them for pasted API keys, passwords, customer information, source code, internal URLs and incident data. Complete URLs may expose query parameters or one-time links, but the reporting does not prove cookies or stored passwords were stolen. Screenshots and chat capture prove content exposure only if enterprise telemetry or preserved extension evidence confirms collection on that endpoint.
Same-day decision: block and remove the extension everywhere, produce a user/device/version exposure roster, and notify affected users not to delete evidence manually. Revoke browser and SSO sessions where affected profiles accessed privileged systems, where token-bearing URLs were used, or where activity cannot be scoped. Rotate credentials, API keys and other secrets only when they appeared in captured pages or AI conversations, or when account telemetry shows misuse. A universal password reset is theater; targeted revocation tied to demonstrated content exposure is the defensible threshold.