A malicious Chrome Web Store extension posing as Perplexity routed users’ searches through attacker-controlled systems and collected browsing data before forwarding people to legitimate search services. Microsoft said the fake add-on, listed as “Search for perplexity ai,” changed Chromium browser search settings via chrome_settings_overrides and used powerful Declarative Net Request permissions to redirect, rewrite, and monitor traffic. The extension used the domain perplexity-ai[.]online instead of the legitimate perplexity.ai; the reported extension ID was flkebkiofojicogddingbdmcmkpbplcd.
Why it matters: Anyone who installed it may have exposed their searches and browsing activity, and the granted permissions could also have supported credential theft if the operator expanded the campaign. Users should remove the extension immediately and, as a precaution, rotate important passwords and review other installed browser add-ons.
Bill Toulas
2026.06.30
100% relevant
This article establishes a distinct browser-extension abuse incident involving a fake Perplexity-branded extension distributed through the Chrome Web Store.
← Back to all stories