A malicious Chrome extension impersonating Perplexity AI recently slipped through browser store checks to monitor user search activity. This threat matters because it targets a popular AI search tool, potentially exposing sensitive queries to attackers. Microsoft Threat Intelligence identified the rogue software before Google removed it from the Chrome Web Store. Users who installed the extension may have had their typing suggestions and search history logged by the attacker.
Microsoft Threat Intelligence identified the malicious add-on before Google removed it from the store
The fake extension functioned by hijacking browser settings to redirect traffic away from legitimate services. It used chrome_settings_overrides to change the default search engine, routing queries to a server controlled by the threat actors. The extension ID flkebkiofojicogddingbdmcmkpbplcd is the specific marker for this malicious package. Google removed the extension shortly after Microsoft alerted them to the impersonation attempt.
Technical analysis reveals the extension used declarativeNetRequest permissions to log searches and view real-time typing suggestions. This mechanism allowed the attackers to capture data as users typed, even before submitting a search. The extension redirected queries through attacker-controlled servers to intercept the data stream. The domain perplexity-ai.online was used to host the malicious redirection logic.
This incident highlights the risk of third-party browser extensions impersonating legitimate software tools. Users should verify extension IDs and review permissions for any AI-related browser add-ons. Microsoft continues to track these impersonation attempts to protect the broader security ecosystem. The removal of the extension limits current exposure, but vigilance remains necessary for similar threats.
Source: GIZMOCHINA




Discussion
0 comments