Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Chrome Extension Compromises User Searches

Malicious Chrome Extension Compromises User Searches

Posted on June 29, 2026 By CWS

Microsoft has uncovered a harmful Chrome extension masquerading as the AI search engine Perplexity, which secretly monitored user search activities. The extension rerouted all search queries and address bar inputs through a server controlled by attackers before displaying actual search results.

Extension Discovery and Removal

Following a responsible disclosure, Google removed the extension from its store. Named “Search for perplexity ai” and identified by ID flkebkiofojicogddingbdmcmkpbplcd, it utilized a deceptive domain, perplexity-ai[.]online, mimicking the legitimate perplexity.ai. Microsoft’s Defender research team highlighted the extension’s objective to intercept searches and gather data, although no evidence of password theft was found, indicating access beyond normal search functionalities.

Technical Details and Impact

Upon installation, this extension set itself as the browser’s default search engine. It initially directed search queries to perplexity-ai[.]online, where the attacker’s server logged details like browser headers, IP addresses, and user agents. Subsequently, users were redirected to genuine search engines such as Perplexity, Google, or Bing, masking the initial data theft.

The extension further compromised user privacy by redirecting live search suggestions (suggest_url) to the malicious domain, allowing attackers to capture every typed character. This action appeared to be a deliberate data collection effort, leveraging the declarativeNetRequest permissions to log requests and potentially execute WebAssembly code for further exploitation.

Security Measures and Recommendations

This incident is part of a broader trend of malicious extensions exploiting AI branding to deceive users. The differences in this case lie in targeting search queries and address bar inputs rather than AI chats. Microsoft’s research linked similar malicious activities to approximately 900,000 installations across over 20,000 company networks.

Users who installed “Search for perplexity ai” should remove it immediately and verify their default search engine settings. Microsoft advises organizations to enforce strict extension approvals, monitor for altered search settings, and scrutinize unusual extension permissions and domain traffic. It is crucial to approach AI-branded tools with caution, ensuring verification of publishers and domains before installation.

While the identity of the operator remains unknown, and the number of affected users was not disclosed, this incident highlights the importance of vigilance in managing browser extensions and maintaining cybersecurity.

The Hacker News Tags:AI branding, browser extensions, browser security, Chrome security, Cybersecurity, data interception, malicious extensions, Microsoft Defender, search security, web security

Post navigation

Previous Post: U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
Next Post: Oracle E-Business Suite Vulnerability Actively Exploited

Related Posts

Speagle Malware Exploits Security Software for Data Theft Speagle Malware Exploits Security Software for Data Theft The Hacker News
APT28’s New PRISMEX Malware Campaign Targets Ukraine APT28’s New PRISMEX Malware Campaign Targets Ukraine The Hacker News
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft Copilot The Hacker News
GlassWorm Attack Exploits Open VSX Extensions to Target Developers GlassWorm Attack Exploits Open VSX Extensions to Target Developers The Hacker News
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks The Hacker News
How Smart MSSPs Using AI to Boost Margins with Half the Staff How Smart MSSPs Using AI to Boost Margins with Half the Staff The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dell Wyse Security Flaws Allow Remote Code Attacks
  • Oracle E-Business Suite Vulnerability Actively Exploited
  • Malicious Chrome Extension Compromises User Searches
  • U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dell Wyse Security Flaws Allow Remote Code Attacks
  • Oracle E-Business Suite Vulnerability Actively Exploited
  • Malicious Chrome Extension Compromises User Searches
  • U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark