Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke

Microsoft researchers flagged a counterfeit Perplexity Chrome extension that routed queries and omnibox input through an attacker server before completing the search.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke
Share

Key points

  • A Chrome extension impersonating Perplexity AI logged every query and every address-bar keystroke before redirecting users to real results.
  • Microsoft identified it and disclosed it to Google, which removed it from the Chrome Web Store.
  • The extension acted as a man-in-the-middle for the browser's address bar, not a passive credential stealer.
  • Affected users will likely never receive a breach notification; no formal trigger exists for an extension-store takedown.
  • Anyone who installed a Perplexity-branded extension from a third-party publisher should treat their browsing history as compromised.

What made this extension different from a simple info-stealer?

This wasn't a credential harvester waiting for a login form. The extension intercepted keystrokes as they were typed into the omnibox (the Chrome address bar that doubles as a search box), forwarded them to an attacker-controlled server, and only then sent the user on to legitimate results. From the victim's seat, the browser behaved normally throughout.

Anything entered into that bar was at risk: internal hostnames, session URLs carrying authentication tokens, half-typed medical or financial queries, draft questions to a chatbot. Exfiltration happened character by character, before the user finished typing.

Microsoft has not publicly disclosed the number of installs, how long the extension was live, or where the command-and-control infrastructure sat at time of writing.

Our 25 June report on a Featured Chrome ad blocker carrying dormant JS injection capability flagged the same distribution channel: the Chrome Web Store, used as low-friction cover for surveillanceware dressed up as a useful tool. The brand-recognition of AI products does the social-engineering work for the attacker.

Should you worry about notification?

Probably not, because none is coming. There's no formal breach-notification trigger for an extension-store takedown. Google isn't a data controller for what the extension exfiltrated, and Microsoft is the discoverer rather than the custodian. In the EU and UK, the operator of the extension would hold controller status for any intercepted personal data, and that operator is unreachable.

What affected users should do

If you installed a Perplexity-branded Chrome extension from a third-party publisher recently, treat your browsing telemetry as exposed. Remove it, then audit chrome://extensions for anything unfamiliar. Rotate credentials for any service where you may have typed a session-bearing URL or token into the address bar. Check chrome://settings/syncSetup to confirm the extension hasn't propagated to other devices on the same Google account via sync.

For enterprise admins: pull extension inventory from your endpoint console and block by install ID once Microsoft publishes the manifest hash. Force-install policies via Chrome Enterprise are the cleanest defence against future lookalikes.

Verify the real Perplexity extension by publisher identity rather than by name or icon. Both are trivially cloneable.

The judgement call: The omnibox interception angle is the part worth watching. Most extension-based malware goes after cookies or form data after the fact; capturing raw keystrokes from the address bar as they're typed is a harder problem for users to reason about, because nothing looks wrong. The installs figure, when Microsoft releases it, will tell us how far this actually reached.

© 2026 Threat Vectr