Close Menu
    What's Hot

    Maersk raises profit guidance as new US tariffs fuel demand

    NFL: Detroit Lions release Terrion Arnold after judge sets bail at $1m as cornerback charged with leading plot to kidnap three people | NFL News

    Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs

    Facebook X (Twitter) Instagram
    Trending
    • Maersk raises profit guidance as new US tariffs fuel demand
    • NFL: Detroit Lions release Terrion Arnold after judge sets bail at $1m as cornerback charged with leading plot to kidnap three people | NFL News
    • Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs
    • Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
    • What the U.S. Owes Venezuela
    • 1stdibs: A Marketplace That Has Yet To Deliver On Its Growth Promise (NASDAQ:DIBS)
    • ICC Women’s T20 World Cup: Ashleigh Gardner says Australia must be wary of West Indies captain Hayley Matthews’ firepower in semi-final | Cricket News
    • “It’s the energy. Joy’: Brazil’s connection to music and dance persist as the Selecao chase World Cup glory
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

    adminBy adminJune 29, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJun 29, 2026Browser Security / Web Security

    Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

    Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.

    Microsoft says Google removed it from the store after responsible disclosure. The extension was called “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd) and used a look-alike domain, perplexity-ai[.]online, to pass for the real service at perplexity.ai.

    Microsoft’s Defender research team says the point was to intercept searches and collect data. It found no proof of password theft, but far more access than a search box should ever need.

    Once installed, the extension sets itself as the browser’s default search engine. When you searched, the query went first to perplexity-ai[.]online, where the attacker’s server logged it with your browser headers, IP address, and user agent.

    Cybersecurity

    A rule then bounced you to a real search engine (Perplexity, Google, or Bing), so the results looked normal. The theft happened on that first stop, before the redirect.

    The address bar made it worse. The extension also pointed the browser’s live search suggestions (the suggest_url) to the same attacker domain. So your input went to the attacker’s server before you pressed Enter. Not just finished searches, but every character as you typed it.

    Chrome permits search-provider overrides, and legitimate extensions use them. Rewriting and redirecting your traffic is the part a search box has no business doing. This one asked for the declarativeNetRequest family of permissions to do exactly that, then shipped server-side code that logged every request. Microsoft calls that proof the collection was deliberate, not a side effect of the redirect.

    The extension also shipped disabled redirect rules for Google and Bing, so the same setup could be switched on for those engines too. It even left room to run WebAssembly code later, which a simple search tool has no reason to do.

    This fits a steady run of malicious extensions that hide behind AI branding. Some swap the default search engine to capture what you type. Others hijack the search provider or skim ChatGPT and DeepSeek chats. Microsoft’s own research tied that chat-skimming wave to roughly 900,000 installs across more than 20,000 company networks.

    Cybersecurity

    The difference here is the target: not your AI chats, but your searches and the characters you type into the address bar, collected through Chrome’s own extension machinery.

    If you installed “Search for perplexity ai,” remove it and check that your default search engine has not been changed. For teams, Microsoft suggests the basics:

    • Allow only approved extensions through the browser or company policy.
    • Watch for changed search settings, strange extension permissions, and traffic to unfamiliar domains.
    • Treat AI-branded tools with extra suspicion, and check the publisher and domain before installing.

    No one has been named as the operator, and Microsoft did not say how many people installed it before the takedown. The AI branding got the install. The search override did the collecting.

    address Bar Chrome extension Input Intercepted malicious Perplexity searches
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleIsraeli attacks kill four men and a boy in Gaza and a teenager in West Bank | Israel-Palestine conflict News
    Next Article Sinner’s shaky start raises questions — is he vulnerable at Wimbledon?
    admin
    • Website

    Related Posts

    Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

    June 29, 2026

    WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private

    June 29, 2026

    Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More

    June 29, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Maersk raises profit guidance as new US tariffs fuel demand

    NFL: Detroit Lions release Terrion Arnold after judge sets bail at $1m as cornerback charged with leading plot to kidnap three people | NFL News

    Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs

    Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by