Fake Perplexity Extension: Warning for Chrome Users

Fake Perplexity Extension: Warning for Chrome Users

If you rely on Perplexity AI to streamline your online searches, a new threat could be lurking in your Chrome browser. Microsoft recently uncovered a malicious Chrome extension disguised as a legitimate Perplexity AI tool—a Fake Perplexity extension that secretly redirects your search queries through attacker-controlled servers. This post breaks down how the scam works, why it’s dangerous, and what steps you need to take to protect yourself.

What Is the Fake Perplexity Extension?

The Fake Perplexity extension is a deceptive browser add-on that mimics the popular Perplexity AI assistant. Unlike the authentic Perplexity extension, which provides AI-powered search summaries, this fraudulent version is designed to intercept your online activity. Once installed, it reroutes your search terms—everything from product reviews to private questions—through servers operated by cybercriminals. This technique, known as a man-in-the-middle attack, allows attackers to monitor, modify, or steal your data in real time.

Microsoft’s Threat Intelligence team first detected the malware in early 2025, warning Chrome users that the extension had abused Chrome’s built-in search features to persist in browsers undetected. The malicious code exploited legitimate APIs to blend in with normal browser behavior, making it difficult for even savvy users to spot the difference.

How Does the Fake Perplexity Extension Work?

The Fake Perplexity extension gains a foothold through a classic social engineering tactic: convincing users to install a “helpful” tool. It might appear in Chrome Web Store listings (if it hasn’t been taken down yet) or be pushed via phishing emails, malicious ads, or compromised websites. Once added to your browser, it silently activates.

Here’s the step-by-step breakdown:

1. Initial Installation: The extension poses as a productivity tool, often with a convincing logo and description similar to the real Perplexity AI extension.
2. Search Hijacking: When you type a query into Chrome’s address bar or a search engine, the extension intercepts the request. Instead of sending it to Perplexity’s servers, it forwards the data to a remote attacker server.
3. Data Harvesting: Attackers can collect your search history, login credentials, credit card numbers, or personal identifiable information (PII) from the requests. They may also inject malicious links or ads into search results to direct you to phishing sites.
4. Exfiltration and Abuse: Stolen data is used for identity theft, financial fraud, or sold on the dark web.

The most alarming aspect is that the extension remains active in the background, even after you close Chrome. It can also update itself to avoid detection by security software.

Why Chrome Users Are at Risk

Chrome is the most widely used browser globally, and its vast extension ecosystem makes it a prime target for attackers. The Fake Perplexity extension exploits several Chrome features:

Permissions Abuse: The extension requests broad permissions, such as “access to your data on all websites,” which users often grant without a second thought.
Auto-Update Mechanism: Malicious extensions can push updates to add new features, including additional data-stealing capabilities.
Persistence: Some versions disguise themselves as helper extensions for Google services, making them harder to remove without manual intervention.

Microsoft’s report highlights that this isn’t a one-off incident. The attackers behind the Fake Perplexity extension have used similar tactics to impersonate other AI tools, including ChatGPT and Claude. The scale of the campaign suggests a coordinated effort to target users who are seeking productivity enhancements.

How to Identify and Remove the Fake Perplexity Extension

If you suspect you’ve installed the Fake Perplexity extension, take immediate action. Here’s a checklist to verify and clean your browser:

Check Your Extensions List

1. Open Chrome and type `chrome://extensions` in the address bar.
2. Look for any extension named “Perplexity AI” or similar variants (e.g., “Perplexity Assistant,” “Perplexity Search”).
3. Verify the extension’s developer name. The authentic Perplexity extension is published by “Perplexity AI, Inc.” Look for typos or unusual phrasing.
4. Check the permissions requested. If it asks for access to “all websites,” “your data on all websites,” or “read and change your browsing history,” it’s a red flag.

Manually Remove Suspicious Extensions

– Disable the extension by toggling off the slider, then click “Remove” to delete it completely.
– After removal, clear your browsing data: Go to `chrome://settings/clearBrowserData` and select “All time” for time range. Check “Cached images and files” and “Site data.”
– Run a full system scan with trusted antivirus software, such as Windows Defender or Malwarebytes, to catch any residual malware.

Enable Safe Browsing Mode

– In Chrome settings, go to “Privacy and security” > “Security” and turn on “Enhanced protection” for Google Safe Browsing. This helps block dangerous extensions before they install.

Preventing Future Malicious Extensions

The best defense against a Fake Perplexity extension—and similar threats—is proactive caution. Follow these best practices to keep your browser secure:

Stick to Official Sources: Only install extensions from the Chrome Web Store and verify they have a high number of positive reviews. Look for recent updates and developer responsiveness.
Scan Permissions Carefully: Reject extensions that request unnecessary permissions. A search tool shouldn’t need access to your camera, microphone, or all website data.
Monitor Browser Behavior: If you notice unusual redirects, pop-ups, or slow performance, immediately check for unfamiliar extensions.
Regularly Audit Your Extensions: Review your extension list weekly. Remove any you don’t recognize or no longer use.

The Final Warning

The Fake Perplexity extension is a stark reminder that even trusted productivity tools can be weaponized. As AI-powered assistants become more popular, cybercriminals will continue to exploit that trust. To avoid falling victim, treat every extension request with skepticism, especially when it promises to enhance your search experience.

If you’ve already installed this malicious extension, act now: remove it, change your passwords for all online accounts, and monitor your credit reports for signs of identity theft. Stay vigilant, and remember: a small inconvenience in verifying an extension’s authenticity is far better than the costly repercussions of a data breach. For the latest updates on this evolving threat, bookmark TechRepublic’s security coverage and share this warning with fellow Chrome users. Your data—and your digital safety—depend on it.

Leave a Reply

Your email address will not be published. Required fields are marked *