Back to all lessons
Awareness Lessons
3 months ago

Fake AI Extension Hijacks Search Queries via Chrome Web Store

A malicious Chrome extension impersonated the popular Perplexity AI tool to silently intercept and exfiltrate user search queries and browsing data. The attack exploited user trust in the Chrome Web Store as a perceived safe distribution channel, combined with low awareness of extension permission risks. This matters because browser extensions operate with deep access to web activity, making them a high-value vector for data harvesting, credential theft, and persistent surveillance. The incident highlights how supply chain threats can exist even within official marketplaces, where vetting processes are insufficient to catch all malicious actors.

Tactical Insight

Immediate actions

  • Audit all installed browser extensions across the organization and remove any that are unverified, unnecessary, or impersonating legitimate tools.
  • Report and flag suspicious extensions to the Chrome Web Store security team for expedited review and removal.

Long-term improvements

  • Enforce browser extension allowlisting policies via MDM or group policy to prevent installation of unapproved extensions.
  • Establish a formal approval process for browser extensions that includes permission review and vendor verification before organizational use.
  • Train employees to scrutinize extension permissions, publisher identity, and review counts before installing any browser add-on.

Detection measures

  • Deploy endpoint monitoring tools capable of detecting unusual browser extension installations or unexpected outbound data routing.
  • Monitor DNS and network traffic for connections to unknown or suspicious infrastructure originating from browser processes.