Fake Perplexity Chrome Extension Was Quietly Stealing Your Searches

Microsoft found a malicious Chrome extension posing as Perplexity’s AI search engine — and it was logging everything you searched for and typed into the address bar.

The extension, called “Search for perplexity ai” (ID: flkebkiofojicogddingbdmcmkpbplcd), used a look-alike domain — perplexity-ai[.]online — to impersonate the real service. Once installed, it set itself as the default search engine. Every query went to the attacker’s server first, where it was logged along with your IP address, browser headers, and user agent. Then you got bounced to the real search results.

But it got worse. The extension also pointed the browser’s live search suggestions to the attacker’s domain. That means every character you typed in the address bar was sent to them before you pressed Enter. Not just finished searches — your half-typed thoughts, mistakes, and all.

Google pulled the extension from the Chrome Web Store after Microsoft disclosed the issue. Microsoft’s Defender research team found no evidence of password theft, but said the extension asked for far more permissions than any search tool should need. It used Chrome’s declarativeNetRequest permissions to rewrite and redirect traffic, and even included disabled redirect rules for Google and Bing — suggesting the same setup could target those engines too.

This isn’t isolated. Malicious extensions hiding behind AI branding have been a growing problem. Some swap default search engines to capture queries. Others skim ChatGPT conversations. Microsoft’s own research tied one chat-skimming wave to roughly 900,000 installs across more than 20,000 company networks.

If you installed this extension, remove it and check whether your default search engine was changed. For organizations, stick to approved extensions and watch for unusual browser settings or traffic to unfamiliar domains.

References