HomeSecurityMalicious Perplexity Chrome extension intercepts searches in the Address Bar

Malicious Perplexity Chrome extension hijacks Address Bar searches

Microsoft has discovered a malicious Chrome extension that posed as the AI ​​Perplexity search engine and silently recorded users' searches. The extension redirected every query and character typed into the address bar through a server controlled by the attacker, before directing users to the real results.

See also: Claude Chrome Extension: Vulnerability allows full control of AI agent

Perplexity

Microsoft says Google removed it from the store after being notified. The extension was called “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd) and used a similar domain, perplexity-ai[.]online, to resemble the real service at perplexity.ai.

The Microsoft Defender research team says the goal was to intercept searches and collect data. There was no evidence of password theft, but there was far more access than a search box should ever have.

Once installed, the extension set itself as the browser's default search engine. When you performed a search, the query first went to perplexity-ai[.]online, where the attacker's server recorded it along with the browser headers, IP address, and user. A rule then redirected you to a real search engine (Perplexity, Google, or Bing) so that the results looked normal. The theft occurred in this first step, before the redirect.

The address bar made it worse. The extension also directed the browser's live search suggestions (suggest_url) to the same domain as the attacker. So your input was going to the attacker's server before you hit Enter. Not just the completed searches, but each character as you typed them.

Chrome allows search provider replacement, and legitimate extensions use it. Rewriting and redirecting your traffic is something a search box has no business doing. This extension invoked the declarativeNetRequest to do just that, and then sent server-side code that logged every request.

See also: Chrome: Popular ad blocker extension allowed code injection

malicious Chrome extension - SecNews.gr

Microsoft sees this as evidence that the collection was intentional, not a side effect of the redirect. The extension also sent disabled redirect rules for Google and Bing, so that the same setting could be enabled for those engines as well. It even left room to execute WebAssembly later, something a simple search tool has no reason to do.

This fits in with a steady stream of malicious extensions hiding behind the AI ​​brand. Some change your default search engine to record what you type. Others take over your search provider or monitor ChatGPT and DeepSeek conversations. Microsoft’s own research links this wave of chat monitoring to about 900,000 installations across more than 20,000 corporate networks.

The difference here is the target: not your conversations with AI, but your searches and the characters you type in the address bar, collected through Chrome’s own extensions engine. If you installed “Search for perplexity ai,” remove it and check that your default search engine hasn’t changed. For Teams, Microsoft recommends the following:

  • Only allow approved extensions through your browser or company policy.
  • Watch for changes to search settings, strange extension permissions, and traffic to unknown domains.
  • Treat AI-branded tools with extra suspicion and check the publisher and domain before installation.

See also: Chrome: Malicious extension “ChatGPT Ad Blocker” steals conversations

Malicious Perplexity Chrome extension hijacks Address Bar searches

No one has been named as the operator, and Microsoft did not say how many people installed it before the removal. The AI ​​brand carried out the installation. The search replacement did the collection.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS