In last two days, my friend had her CC stolen and Instagram taken over which she accessed from her Mac. Although a rootkit is possible, her browser had three extensions: ublock origin, Google Drive, and "WebChatGPT" [1].
Looking into WebChatGPT:
- It has full access to all sites
- Extension was recently sold by owner [2]
- Latest release [3] doesn't match any new commits in the open-source repo [4].
- The last change in the repo removes sponsor link for buy me a coffee
- Someone opened an issue on the repo calling out spyware [5]
What is the best course of action here? Where can we report this? I am going to try to download the extension and follow where the data is sent.
* 1 https://tools.zmo.ai/webchatgpt
* 2 https://www.buymeacoffee.com/anzorq
* 3 https://addons.mozilla.org/en-US/firefox/addon/web-chatgpt/versions/
* 4 https://github.com/interstellard/chatgpt-advanced
* 5 https://github.com/interstellard/chatgpt-advanced/issues/203