Search for perplexity ai malicious Chrome extension
Malware Activity
Summary
Hide ▲
Show ▼
A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information through perplexity-ai[.]online. The extension replaced the default search provider, routed address-bar queries and real-time suggestions through attacker-controlled infrastructure, and then redirected users to legitimate search results. Microsoft Threat Intelligence said it found no evidence of credential theft, but the extension’s permissions and logging could support broader profiling. Google removed the extension after responsible disclosure, and users who installed the ID flkebkiofojicogddingbdmcmkpbplcd were advised to remove it and rotate critical passwords.
Related Happenings
ModHeader browser extension hidden browsing-history collector
Malware Activity
H score42
First: 13.07.2026 20:17
Last: 13.07.2026 20:17
Sources 1
About this happening:
The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
ModHeader browser extension hidden browsing-history collector
Malware ActivityAbout this happening: The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
Silent Swap browser-extension clipboard clipper
Malware Activity
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension clipboard clipper
Malware ActivityAbout this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
LayerX BioShocking prompt injection against agentic browsers
Technical Analysis
H score30
First: 24.06.2026 19:05
Last: 24.06.2026 19:05
Sources 1
About this happening:
Researchers demonstrated BioShocking, a prompt-injection technique that pushed six agentic browsers and plugins past guardrails and made them copy login credentials fo...
LayerX BioShocking prompt injection against agentic browsers
Technical AnalysisAbout this happening: Researchers demonstrated BioShocking, a prompt-injection technique that pushed six agentic browsers and plugins past guardrails and made them copy login credentials fo...
Timeline
-
29.06.2026 21:40 3 articles · 16d ago
Malicious Perplexity Chrome extension intercepted searches and address-bar input
Initial DisclosureMicrosoft identified a malicious Chrome extension named "Search for perplexity ai" that impersonated Perplexity through perplexity-ai[.]online, set itself as the browser default search engine, intercepted search queries and live address-bar suggestions, and logged browser headers, IP address, and user agent before redirecting users to real search results. Google removed the extension from the store after responsible disclosure.
Show sources
- Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input — thehackernews.com — 29.06.2026 21:40
- Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input — thehackernews.com — 29.06.2026 21:40
- Fake Perplexity extension on Chrome Web Store tracked searches — www.bleepingcomputer.com — 30.06.2026 18:46