Malware · 76 days ago
A browser extension can sit in the search path and collect user input before the browser ever reaches a real search engine. In this case, a Chromium add-on posing as Perplexity AI rewrote search settings so queries and live suggestions went to attacker-controlled infrastructure first, then sent users on to normal results so the browser still looked ordinary.
Microsoft said the extension used MV3 permissions and redirect rules to intercept full search queries, typed address-bar suggestions, IP addresses, headers, and browser metadata. Google has removed it, and Microsoft found no proof of password theft, but the access was broad enough to turn search traffic into a quiet collection point for profiling and other misuse. That matters anywhere third-party extensions are allowed, especially when they are wrapped in AI branding.
4 sources covering this story
Fake Perplexity extension on Chrome Web Store tracked searches
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information.
Malicious Chromium extension spoofs Perplexity AI to hijack browser searches
Researchers say attackers are extending AI-themed social engineering from phishing campaigns to browser extensions.
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Microsoft says a fake Perplexity Chrome extension logged searches, IPs, headers, and address bar input before redirecting users.
Chromium extension uses AI‑related branding to redirect browser search | Microsoft Security Blog
A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure.
Part of the PlainSec briefing for 2026-07-01