A malicious Chrome extension impersonating the Perplexity AI search engine has been intercepting user searches and collecting browsing data. The fraudulent extension was discovered on the official Chrome Web Store.
Security researchers identified a fake Perplexity extension distributed through the Chrome Web Store that captured search queries and user browsing information without consent.
The malicious extension mimicked the legitimate Perplexity AI answer engine, making it difficult for users to distinguish from the authentic tool. Once installed, it intercepted search traffic and collected sensitive browsing data, exposing users to privacy violations.
The discovery highlights ongoing security vulnerabilities in app marketplaces. Chrome Web Store relies partially on automated detection systems, which can miss sophisticated impersonation attempts. The fake extension remained available for an undetermined period before removal.
Perplexity AI has not confirmed an official Chrome extension, making any Perplexity-branded extension on the Web Store potentially suspicious. Users should verify extension authenticity by checking developer information and reviewing permissions before installation.
This incident joins a growing category of supply chain attacks targeting popular AI tools. Similar schemes have targeted ChatGPT, Google Bard, and other widely-used AI platforms. Attackers leverage legitimate brand recognition to bypass user skepticism.
Recommended actions:
- Remove any unfamiliar Perplexity extensions
- Check installed extensions for suspicious permissions
- Access Perplexity through perplexity.ai directly
- Enable Chrome's enhanced safe browsing
Google has removed the extension from the Web Store. Users who installed it should review their browsing history and monitor accounts for suspicious activity. The incident underscores the importance of downloading tools only from verified sources and reviewing extension permissions carefully.
Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.
A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.
McKesson, a major healthcare and pharmaceutical distributor, confirmed a cybersecurity incident involving unauthorized access to third-party applications. Extortion group ShinyHunters claims responsibility for stealing 284 million patient data records.
Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.