Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
2026-06-30T01:24:10Z•0d52aeedf844e945dfa949676d6d3527b52076c2980e37d09925dbef64883eeb
APTCobalt-StrikeDirtyCloneMustang-PandaPTC-WindchillTurlaarbitrary-js-injectionbrowser-extension-malwarechrome-extensioncrypto-scamsedge-extensiongoinfostealerknown-exploited-vulnerabilitylibssh2linux-kernel-privilege-escalationnodejs-implantnpmpedit-COWsignal-phishingsteganographysupply-chainsupply-chain-attacks
What happened
A broad set of active threats and high‑risk vulnerabilities was reported: malicious browser extensions (a Perplexity‑themed Chrome extension that exfiltrated searches and address‑bar input; a popular Chrome adblocker capable of arbitrary JS; and 119 Edge extensions using steganography to hide payloads) and multiple supply‑chain compromises (hijacked npm/Go packages, GitHub Actions abuse, and Miasma/Mini Shai‑Hulud deployments). Several high‑severity and publicly exploited vulnerabilities were highlighted, including a public PoC for libssh2 (CVE‑2026‑55200, CVSS 9.2), Linux local privilege‑escl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0d52aeedf844e945dfa949676d6d3527b52076c2980e37d09925dbef64883eeb
- Enrichment time
- 2026-06-30T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.