Back to all lessons
Awareness Lessons
3 months ago

Fake AI Browser Extension Hijacks Search and Harvests User Data

A malicious browser extension impersonated the legitimate Perplexity AI brand to deceive users into installing it, then silently redirected search queries and collected browsing data using Manifest V3 APIs and intermediary infrastructure. The attack exploited users' trust in recognizable AI branding and the relatively permissive nature of browser extension ecosystems. This matters because browser extensions operate with significant privileges inside the browser, making them a high-value vector for data theft and search manipulation. The incident highlights the risks of installing extensions without verifying publisher authenticity, and underscores how threat actors are capitalizing on AI hype to social-engineer victims.

Tactical Insight

Immediate actions

  • Audit all currently installed browser extensions across the organization and remove any that are unverified, unused, or impersonating known brands.
  • Alert end users to the specific threat of AI-branded extensions and instruct them to verify publisher identity before installation.

Long-term improvements

  • Enforce browser extension allowlisting policies via enterprise MDM or browser management tools so only approved extensions can be installed.
  • Establish a formal vetting process for third-party browser extensions that includes publisher verification, permission review, and periodic re-evaluation.
  • Integrate supply chain risk considerations into software procurement and acceptable-use policies to cover browser plugins and extensions.

Detection measures

  • Deploy endpoint detection tools capable of monitoring browser extension installations and flagging new or unapproved additions.
  • Enable centralized logging of browser extension activity and configure alerts for extensions requesting sensitive permissions such as search interception or data exfiltration.