Affected Systems
Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.
Exploitation Status
Active campaign confirmed. Malicious extension was live on Chrome Web Store, actively targeting users searching for Perplexity AI tools. Extension has been discovered but removal status from store not specified.
Business Impact
Users who installed the fake extension face search traffic interception and browsing data exfiltration. Risk of credential theft, session hijacking, and corporate data leakage if used on managed devices. Supply chain risk as users trust Chrome Web Store as vetted source. No CVE assigned as this is a campaign rather than software vulnerability.
Urgency
🟠Within 24 hours
Recommended Actions
- Audit all Chrome extensions installed across the organization using Chrome Browser Cloud Management or GPO, specifically searching for Perplexity-related extensions
- Remove any unauthorized Perplexity AI extensions immediately; the legitimate Perplexity service is web-based and does not require a Chrome extension
- Review Chrome extension policies to enforce allowlists or require admin approval for new extension installations
- Monitor web proxy logs and DNS queries for unusual search redirection patterns or data exfiltration to unknown domains
- Educate users on supply chain risks of browser extensions and verify legitimacy through official vendor channels before installation
