Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

2026-06-30T01:24:10Z0d52aeedf844e945dfa949676d6d3527b52076c2980e37d09925dbef64883eeb
APTCobalt-StrikeDirtyCloneMustang-PandaPTC-WindchillTurlaarbitrary-js-injectionbrowser-extension-malwarechrome-extensioncrypto-scamsedge-extensiongoinfostealerknown-exploited-vulnerabilitylibssh2linux-kernel-privilege-escalationnodejs-implantnpmpedit-COWsignal-phishingsteganographysupply-chainsupply-chain-attacks

What happened

A broad set of active threats and high‑risk vulnerabilities was reported: malicious browser extensions (a Perplexity‑themed Chrome extension that exfiltrated searches and address‑bar input; a popular Chrome adblocker capable of arbitrary JS; and 119 Edge extensions using steganography to hide payloads) and multiple supply‑chain compromises (hijacked npm/Go packages, GitHub Actions abuse, and Miasma/Mini Shai‑Hulud deployments). Several high‑severity and publicly exploited vulnerabilities were highlighted, including a public PoC for libssh2 (CVE‑2026‑55200, CVSS 9.2), Linux local privilege‑escl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0d52aeedf844e945dfa949676d6d3527b52076c2980e37d09925dbef64883eeb
Enrichment time
2026-06-30T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.