Cybersecurity researchers have uncovered a fake Perplexity Chrome extension that impersonated the popular AI search assistant while secretly intercepting users’ search traffic and collecting browsing data. The malicious extension appeared in the Chrome Web Store and redirected address bar searches through attacker-controlled infrastructure before forwarding users to legitimate search services.

Although Microsoft found no evidence that the extension stole passwords or login credentials, researchers warned that its extensive browser permissions could easily support more aggressive attacks in the future.

Fake Perplexity Chrome Extension Hijacked Search Traffic

Microsoft Threat Intelligence discovered the malicious extension, which appeared in the Chrome Web Store under the name “Search for perplexity ai.”

The extension attempted to imitate the legitimate Perplexity AI browser extension by using similar branding and directing users to the domain perplexity-ai[.]online instead of the official perplexity.ai website.

After installation, the fake Perplexity Chrome extension automatically modified Chrome’s default search settings. Instead of sending searches directly to the user’s chosen search engine, it routed every address bar query through attacker-controlled servers before redirecting users to legitimate search providers.

According to Microsoft, the attackers achieved this by abusing Chrome’s chrome_settings_overrides capability to replace the browser’s default search provider and intercept Omnibox searches.

Microsoft Found Extensive Data Collection

Microsoft’s investigation showed that the extension collected far more information than users would expect from an AI assistant.

Researchers discovered logging code on the attackers’ infrastructure that confirmed the data collection formed part of the extension’s intended design rather than an accidental side effect.

The extension also requested several powerful Chrome permissions that allowed it to redirect traffic, rewrite URLs, and monitor when browser rules executed.

Microsoft noted that these permissions have little connection to the normal functionality of an AI-powered search assistant and instead provide broad control over a user’s web traffic.

Researchers Warn of Future Abuse

Although Microsoft found no signs that the fake Perplexity Chrome extension attempted to steal usernames, passwords, or authentication cookies, the company warned that its permissions would have allowed the attackers to expand their operation significantly.

By monitoring browsing activity and search behavior, threat actors could build detailed user profiles for targeted advertising, phishing campaigns, identity theft, or future cyberattacks.

The researchers believe the extension’s ability to intercept traffic created opportunities for much broader data collection if the operators decided to update its functionality.

Users Should Remove the Extension Immediately

Microsoft advises anyone who installed the malicious extension with the ID flkebkiofojicogddingbdmcmkpbplcd to remove it from Chrome immediately.

As an additional precaution, affected users should change passwords for important online accounts, especially if they used the browser while the extension remained installed.

The incident also serves as another reminder that cybercriminals continue to exploit the growing popularity of AI tools by publishing convincing fake browser extensions that closely resemble legitimate applications. Before installing any AI extension, users should verify the developer name, official website, permissions requested, and Chrome Web Store listing to reduce the risk of installing malware disguised as productivity software.


0 responses to “Fake Perplexity Chrome Extension Tracked Users’ Search Activity”