Back to News
Threat Intelligence

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

Cyber RTJune 29, 20263 min read
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

Microsoft discovered a malicious Chrome extension mimicking the AI search engine Perplexity, which logged users' searches by routing queries through an attacker-controlled server. Named "Search for perplexity ai," it used a deceptive domain to intercept data. Google removed it after disclosure. The extension altered search settings and collected data, exploiting Chrome's extension permissions. Users are advised to remove it and monitor for unauthorized changes.

Microsoft recently discovered a malicious Chrome extension masquerading as the AI search engine Perplexity, which secretly logged users' search queries. This extension intercepted every search query and character typed into the address bar, routing them through a server controlled by the attacker before redirecting users to legitimate search results. After Microsoft responsibly disclosed the issue, Google removed the extension from its store. The extension, named "Search for perplexity ai" with the ID flkebkiofojicogddingbdmcmkpbplcd, utilized a deceptive domain, perplexity-ai[.]online, to mimic the genuine Perplexity service at perplexity.ai. Microsoft's Defender research team highlighted that the extension's primary goal was to intercept searches and collect data. Although there was no evidence of password theft, the extension had far more access than necessary for a search tool. Once installed, the extension set itself as the browser's default search engine. It redirected search queries first to the attacker's server at perplexity-ai[.]online, logging them along with browser headers, IP addresses, and user agents. A rule then redirected users to a real search engine, making the results appear legitimate while the data theft occurred during the initial interception. The extension exacerbated the issue by redirecting the browser's live search suggestions (suggest_url) to the attacker's domain. This meant that every character typed into the address bar was sent to the attacker's server before users pressed Enter, not just completed searches. This misuse of Chrome's search-provider override capabilities was a deliberate attempt to collect user data. The extension requested the declarativeNetRequest permissions to rewrite and redirect traffic, which is beyond the scope of a typical search box. It also included server-side code to log every request, indicating intentional data collection rather than an accidental byproduct of the redirect. Additionally, the extension had disabled redirect rules for Google and Bing, suggesting potential expansion to these search engines. This incident is part of a broader trend of malicious extensions exploiting AI branding. Some extensions change the default search engine to capture user input, while others hijack search providers or skim AI chat data. Microsoft's research linked this chat-skimming activity to approximately 900,000 installs across over 20,000 company networks. However, this extension specifically targeted search queries and address bar inputs. Users who installed "Search for perplexity ai" are advised to remove it and verify that their default search engine settings remain unchanged. Microsoft recommends allowing only approved extensions through browser or company policies, monitoring for altered search settings, unusual extension permissions, and traffic to unfamiliar domains. AI-branded tools should be approached with caution, and users should verify the publisher and domain before installation. The operator behind the malicious extension remains unidentified, and Microsoft has not disclosed the number of installations before its removal. The use of AI branding facilitated installations, while the search override mechanism enabled data collection. For more updates and exclusive content, readers are encouraged to follow Microsoft on Google News, Twitter, and LinkedIn.