{"id":1509,"date":"2026-06-29T20:17:23","date_gmt":"2026-06-29T20:17:23","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1509"},"modified":"2026-06-29T20:17:23","modified_gmt":"2026-06-29T20:17:23","slug":"malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1509","title":{"rendered":"Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 29, 2026<\/span><\/span><span class=\"p-tags\">Browser Security \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgOcObOpyIQZzuiNoFu6Lv4jCDh64o1WYrC3stGdk58mMRg69RT56svVrXVwu618f6szk2lj_Tqbt6b7Rg25yV0cauxIDTbMAI8cbftKVYibIt5SMeaOT2zE3oeuu-RLI7M1mkEV3zirqDiO-nLMikX7QixM2EpVIdKQERGc7I_0p58L4J-s5mBjSCpgHc\/s1700-e365\/pp-ai.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.<\/p>\n<p>Microsoft says Google removed it from the store after responsible disclosure. The extension was called \u00abSearch for perplexity ai\u00bb (ID\u00a0flkebkiofojicogddingbdmcmkpbplcd) and used a look-alike domain,\u00a0perplexity-ai[.]online, to pass for the real service at perplexity.ai.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/29\/chromium-extension-uses-airelated-branding-redirect-browser-search\/\">Microsoft&#8217;s Defender research team<\/a>\u00a0says the point was to intercept searches and collect data. It found no proof of password theft, but far more access than a search box should ever need.<\/p>\n<p>Once installed, the extension sets itself as the browser&#8217;s default search engine. When you searched, the query went first to\u00a0perplexity-ai[.]online, where the attacker&#8217;s server logged it with your browser headers, IP address, and user agent.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A rule then bounced you to a real search engine (Perplexity, Google, or Bing), so the results looked normal. The theft happened on that first stop, before the redirect.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The address bar made it worse. The extension also pointed the browser&#8217;s live search suggestions (the\u00a0suggest_url) to the same attacker domain. So your input went to the attacker&#8217;s server before you pressed Enter. Not just finished searches, but every character as you typed it.<\/p>\n<p><a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/reference\/manifest\/chrome-settings-override\">Chrome permits search-provider overrides<\/a>, and legitimate extensions use them. Rewriting and redirecting your traffic is the part a search box has no business doing. This one asked for the\u00a0declarativeNetRequest\u00a0family of permissions to do exactly that, then shipped server-side code that logged every request. Microsoft calls that proof the collection was deliberate, not a side effect of the redirect.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqHW3E71Es3U6eAi9XuW_qcryhIUnObxunOS8DdoLk8u7IC4urSUHr_2G7bO9HDM3LJLZLoTzcahEg7sVRiD7sdfd6pj46qJLsbZVqK1ex-eCMEezhOLPETeQqPjPdCzpni_aX3Uz7NMjubtHhTWmn-ZIC8Y5npG98rlsKQC1bhgZudaiEdS_Pq5xB5Z0\/s1700-e365\/ai-code.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhqHW3E71Es3U6eAi9XuW_qcryhIUnObxunOS8DdoLk8u7IC4urSUHr_2G7bO9HDM3LJLZLoTzcahEg7sVRiD7sdfd6pj46qJLsbZVqK1ex-eCMEezhOLPETeQqPjPdCzpni_aX3Uz7NMjubtHhTWmn-ZIC8Y5npG98rlsKQC1bhgZudaiEdS_Pq5xB5Z0\/s1700-e365\/ai-code.jpg\" alt=\"\" border=\"0\" data-original-height=\"700\" data-original-width=\"990\"\/><\/a><\/div>\n<p>The extension also shipped disabled redirect rules for Google and Bing, so the same setup could be switched on for those engines too. It even left room to run WebAssembly code later, which a simple search tool has no reason to do.<\/p>\n<p>This fits a steady run of malicious extensions that hide behind AI branding. Some\u00a0swap the default search engine to capture what you type. Others\u00a0hijack the search provider\u00a0or\u00a0skim ChatGPT and DeepSeek chats. Microsoft&#8217;s\u00a0<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/03\/05\/malicious-ai-assistant-extensions-harvest-llm-chat-histories\/\">own research<\/a>\u00a0tied that chat-skimming wave to roughly 900,000 installs across more than 20,000 company networks.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The difference here is the target: not your AI chats, but your searches and the characters you type into the address bar, collected through Chrome&#8217;s own extension machinery.<\/p>\n<p>If you installed \u00abSearch for perplexity ai,\u00bb remove it and check that your default search engine has not been changed. For teams, Microsoft suggests the basics:<\/p>\n<ul>\n<li>Allow only approved extensions through the browser or company policy.<\/li>\n<li>Watch for changed search settings, strange extension permissions, and traffic to unfamiliar domains.<\/li>\n<li>Treat AI-branded tools with extra suspicion, and check the publisher and domain before installing.<\/li>\n<\/ul>\n<p>No one has been named as the operator, and Microsoft did not say how many people installed it before the takedown. The AI branding got the install. The search override did the collecting.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jun 29, 2026Browser Security \/ Web Security Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1510,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2241,2242,182,520,2243,2239,33,2238,2240],"class_list":["post-1509","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-address","tag-bar","tag-chrome","tag-extension","tag-input","tag-intercepted","tag-malicious","tag-perplexity","tag-searches"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1509"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1509\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1510"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}