SNACK Quick Summary
- Microsoft has detailed a malicious AI-branded Chromium extension that imitated Perplexity AI.
- The risk is not just a bad search result: the extension could route address-bar queries and live suggestion traffic through attacker infrastructure first.
- Chrome and Edge users should check extension publishers, domains, search-engine changes and high-risk permissions before trusting AI search add-ons.

Snackgirls editor note
Red: “An AI search label is not proof of trust. Address-bar searches can reveal a lot about daily life.”
AIKO: “The tricky part is the redirect. If the user still lands on a normal search page, the interception can stay invisible.”
Nea: “Before installing an extension, the domain and permissions matter more than the name on the button.”
Microsoft Threat Intelligence has published an analysis of a malicious Chromium-based browser extension that spoofed Perplexity AI branding. It looked like an AI search helper, but its real behavior was to change browser search flow and send search requests through attacker-controlled infrastructure first.




What Microsoft found
The analyzed extension used the name Search for perplexity ai and the lookalike domain perplexity-ai[.]online. That is close enough to the legitimate perplexity[.]ai service to create user confusion.
After installation, the extension overrode Chromium search-provider settings. A query typed into the address bar could go to the attacker domain first and then redirect to a legitimate search provider. Because the user still sees search results, the first-hop interception is easy to miss.
Why address-bar traffic matters
Microsoft highlighted that the extension did not only handle finished searches. Its suggest_url setting could route real-time suggestion requests while a person was still typing in the Omnibox.
Search boxes often contain health questions, accounts, work terms, finance queries, travel plans and hobbies. That makes a browser extension that controls the address bar a privacy risk beyond ordinary ad redirection.
What users should check
Users should review installed extensions, especially AI search assistants and productivity add-ons. Check whether the publisher, website and domain match the real service before keeping the extension enabled.
It is also worth checking whether the default search engine changed unexpectedly. Microsoft recommends limiting untrusted extension installs, watching for unusual permissions and relying on reputation-based protections such as Microsoft Defender SmartScreen where available.
Sources and checked date: Checked on June 30, 2026 (KST)
Leave a comment