[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1xq39MeGlfdBV0GWNP-GeJ7d67j9QWASi1c90DAYAeQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"8da8bd71-3822-4d8f-9126-b9c6f5721116","fake-perplexity-chrome-extension-silently-harvested-every-keystroke","60c7a62a-6e9e-4bfb-94e1-c70822307a68","Fake Perplexity Chrome Extension Silently Harvested Every Keystroke","A malicious Chrome extension impersonating the legitimate Perplexity AI tool intercepted and exfiltrated every character users typed into their browser's address bar, including sensitive searches and potentially passwords or URLs containing credentials. The attack exploited user trust in browser extension ecosystems and the growing popularity of AI tools to lure victims into installing spyware. This matters because browser extensions operate with deep, privileged access to browsing activity, making them a high-value, low-friction attack vector. Users rarely scrutinize extension permissions or verify publisher authenticity, creating a significant blind spot in organizational security posture.","**Immediate actions:**\n- Audit all installed browser extensions across the organization and remove any that are unverified, redundant, or not business-justified.\n- Check browser history and network logs for traffic routed through unrecognized third-party servers associated with extension activity.\n- Alert users to uninstall 'Search for perplexity ai' and any similarly named impersonator extensions immediately.\n\n**Long-term improvements:**\n- Enforce an allowlist policy for browser extensions using enterprise browser management tools (e.g., Chrome Enterprise, Edge Policies) so only approved extensions can be installed.\n- Establish a formal vetting process for browser extensions that includes permission review, publisher verification, and source-code inspection where possible.\n- Train employees to recognize supply chain impersonation tactics, including fake AI tool extensions, and to verify extensions via official vendor websites before installing.\n\n**Detection measures:**\n- Deploy DNS or proxy monitoring to flag and block traffic to newly registered or unknown domains originating from browser processes.\n- Implement Data Loss Prevention (DLP) controls capable of detecting anomalous data exfiltration patterns consistent with keylogging behavior.\n- Enable browser telemetry logging and feed it into your SIEM to alert on installation of extensions with high-risk permissions such as 'read all data on websites you visit'.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 AU-12: Audit Record Generation","GDPR Article 5(1)(f): Integrity and Confidentiality","GDPR Article 32: Security of Processing","MITRE ATT&CK T1176: Browser Extensions","MITRE ATT&CK T1056.001: Keylogging","published","2026-06-29T20:20:40.518195+00:00","2026-06-29T20:20:40.249+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fmalicious-perplexity-chrome-extension.html","malicious-perplexity-chrome-extension-intercepted-searches-and-address-bar-input-5ee7da","Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]