Malicious Perplexity-lookalike Chrome extension exfiltrates searches via proxy
Source headline: Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Intelligence Summary
Microsoft identified a malicious Chrome extension impersonating the AI search engine Perplexity. The add-on intercepted users’ searches and even keystrokes entered in the browser address bar. Queries were routed through an attacker-controlled server before users were redirected to legitimate results. This behavior can expose sensitive information such as queries, URLs, and other typed data. Google removed the extension from the Chrome Web Store after responsible disclosure.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.