ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Malicious Perplexity-lookalike Chrome extension exfiltrates searches via proxy

Source headline: Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 month ago

Intelligence Summary

Microsoft identified a malicious Chrome extension impersonating the AI search engine Perplexity. The add-on intercepted users’ searches and even keystrokes entered in the browser address bar. Queries were routed through an attacker-controlled server before users were redirected to legitimate results. This behavior can expose sensitive information such as queries, URLs, and other typed data. Google removed the extension from the Chrome Web Store after responsible disclosure.

Recommended Action

Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#supply-chain #keystroke-logging #browser-privacy #chrome-extension #search-exfiltration
Original reporting The Hacker News Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Open original source