Chromium extension uses AI‑related branding to redirect browser search

2026-06-30T08:52:23Z26cf00ab4b093f5d068135a28e85f5a99587de37c0c0bb087e9e74bcedfd39db
AI browsing agentAmadeyAutoJackMV3 APIMastraPerplexity spoofSapphire SleetStealCai brandingbrowser extension abusechromium extensionfake LNK/shortcuthospitality sectorinfostealerlocalhost abusenode.js implantnpm compromisepersistencephoto ZIP campaignpostinstall payloadremote code executionsearch redirectionsupply chainsupply-chain attacktake down

What happened

This Microsoft Security Blog feed contains multiple June 2026 threat reports and research updates. Key items: a malicious Chromium extension spoofing AI-branded services (Perplexity AI) that uses MV3 extension APIs and intermediary infrastructure to redirect browser search traffic; a multi-stage “photo ZIP” campaign targeting hospitality organizations in Europe and Asia that uses fake image shortcut files to drop a persistent Node.js implant; a technical breakdown and takedown of the StealC and Amadey infostealer ecosystems by Microsoft’s DCU; AutoJack research demonstrating how a maliciousweb

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
26cf00ab4b093f5d068135a28e85f5a99587de37c0c0bb087e9e74bcedfd39db
Enrichment time
2026-06-30T08:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Chromium extension uses AI‑related branding to redirect browser search · Baitaphish