Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Critical Vulnerability Lets Attackers Bypass MFA in Windows 11 and Entra ID
August 10, 2026
Home/Threats/SearchJack Campaign Hijacks 758,000 Users with 23 Malicious Chrome Extensions
Threats

SearchJack Campaign Hijacks 758,000 Users with 23 Malicious Chrome Extensions

Key Takeaways A sophisticated campaign, dubbed “SearchJack,” exploited 23 malicious Chrome extensions to surreptitiously redirect the search queries of approximately 758,000 users. These...

David kimber
David kimber
June 15, 2026 6 Min Read
55 0

Key Takeaways

  • A sophisticated campaign, dubbed “SearchJack,” exploited 23 malicious Chrome extensions to surreptitiously redirect the search queries of approximately 758,000 users.
  • These extensions masqueraded as legitimate tools but silently altered default search settings, routing user queries through undisclosed monetization systems.
  • The operators leveraged Chrome’s chrome_settings_overrides feature, making the hijacking difficult for average users to detect.
  • The campaign poses a significant security risk beyond mere adware, as operators could pivot to delivering phishing content or malicious downloads without requiring extension updates.

A widespread and clandestine operation, now identified as “SearchJack,” has compromised the search activities of nearly three-quarters of a million Chrome users globally. This campaign utilized a network of 23 seemingly innocuous browser extensions to reroute search queries through hidden revenue-generating mechanisms, all without the users’ knowledge or consent.

Table Of Content

  • Key Takeaways
  • How SearchJack Operates
  • Deceptive Practices and Privacy Concerns
  • The Technical Architecture of SearchJack
  • The Broker Network Enabling the Campaign
  • What You Should Do

Each of the malicious extensions presented itself as a beneficial utility, ranging from satellite mapping tools to productivity applications. However, their primary function was to silently execute a search hijacking scheme in the background, funneling user data through a series of intermediary servers before displaying seemingly normal search results.

How SearchJack Operates

The core mechanism of the SearchJack campaign is both simple and remarkably difficult to detect. Upon installation, these extensions exploit a legitimate Chrome feature, chrome_settings_overrides, to forcibly change the browser’s default search engine. When a user subsequently initiates a search, their query is first directed through servers controlled by the campaign’s operators. This process adds a monetization layer to every search, a step entirely hidden from the user, before the query finally reaches its intended destination, typically Yahoo, displaying what appears to be an unadulterated search results page. For a detailed technical analysis, refer to the report by MalExt Sentry.

The campaign was brought to light by researchers at MalExt Sentry, who utilized their automated scanning system to monitor Chrome extension listings for suspicious activities. According to their report shared with Cyber Security News (CSN), the scanner specifically identified extensions that were misusing the chrome_settings_overrides manifest key to seize control of browser search settings.

MalExt Sentry’s investigation uncovered at least eight distinct affiliate brokers involved in the campaign, each uniquely identified by a specific tracking parameter appended to the final Yahoo redirect URL. This network of brokers is crucial to the campaign’s monetization strategy.

Deceptive Practices and Privacy Concerns

A significant challenge in detecting SearchJack lies in the discrepancy between the extensions’ advertised functionality and their actual behavior. For instance, the extension “Nautilus Search” explicitly claimed in its Chrome Web Store listing that it would neither track searches nor collect personal data. However, its linked privacy policy directly contradicted this, revealing that it collected IP addresses, search queries, and device identifiers.

This deliberate misrepresentation is not merely an oversight; it constitutes a false claim that could potentially lead to legal action under regulations such as GDPR and FTC frameworks. The broad scope of this campaign raises serious concerns that extend beyond misleading descriptions. Because the operators maintain control over where search traffic is directed, they possess the ability to covertly shift from delivering standard search results to serving malicious content, such as phishing pages or drive-by downloads, without needing to push any updates to the installed extensions. This inherent capability to escalate harm, without altering the visible code, transforms SearchJack from simple adware into a significant cybersecurity threat.

The Technical Architecture of SearchJack

The SearchJack campaign’s technical infrastructure is designed for stealth, employing a multi-layered redirect system. Many of the identified extensions are “shell extensions,” containing minimal code beyond the manifest file that reconfigures the default search engine. These extensions typically lack background scripts, do not request overt permissions, and offer no visual cues of their malicious activity. A common structural template is observed across numerous extensions, with only the domain and icon being altered to create new variants.

A smaller subset of these extensions incorporates rudimentary, fake functionalities, such as basic map viewers or video libraries. These superficial features serve to bypass automated review processes in the Chrome Web Store and to lend an air of legitimacy to the installation. While largely non-functional, they are sufficient to prevent immediate removal. For example, the “Search Toggler” extension presents users with an interface that purports to allow switching between different search engines. In reality, all queries are still routed through the operator’s servers, irrespective of the user’s selection. The critical routing logic is injected at runtime, making it invisible to conventional static analysis tools.

The Broker Network Enabling the Campaign

At the heart of the SearchJack campaign lies a network of brokers, each operating under a revenue-sharing agreement with Yahoo’s search affiliate program. These brokers earn a commission for every search query routed through their system. The campaign involves at least eight distinct brokers, with a substantial portion of the activity linked to an unidentified operator.

While some brokers, like Dublin-based Becovi Ltd, have a traceable identity, others remain anonymous, complicating efforts for accountability and enforcement. An intriguing case involves “Fusebase Search,” an extension published under a legitimate company name, which displayed 609 reviews against a mere 490 current installations. This statistically improbable ratio suggests either sophisticated review manipulation or a prior policy violation that led to a reset of its installation count.

Researchers advocate for enforcement actions to target the broker level rather than individual extensions. This strategy is based on the understanding that while extensions are easily replaced, the underlying affiliate accounts represent a more persistent vulnerability. Users are strongly advised to regularly audit their installed extensions, remove any unfamiliar or suspicious items, and manually verify and reset their default search engine settings within Chrome.

What You Should Do

  • Audit Your Extensions: Regularly review all installed Chrome extensions. Remove any extensions that seem unfamiliar, were installed without your explicit intent, or offer functionality you no longer need.
  • Verify Search Settings: Manually check your default search engine in Chrome’s settings. Navigate to chrome://settings/search and ensure your preferred search engine is selected. If it has been changed without your knowledge, reset it.
  • Be Skeptical of “Free” Tools: Exercise caution when installing new browser extensions, especially those offering free services like maps, video libraries, or productivity tools. Always scrutinize their privacy policies, even if the store description seems benign.
  • Report Suspicious Extensions: If you identify an extension exhibiting behavior similar to SearchJack, report it to the Chrome Web Store.
  • Consider Browser Security Tools: Utilize browser security extensions or anti-malware software that specifically monitors for browser hijacks and unwanted program installations.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain myperfecttab[.]com PerfecTab Search redirect domain
Domain query.quicksearchtool[.]com Quick Search Tool redirect domain
Domain search.getbettersearch-api[.]com Better Search redirect domain
Domain newtab[.]club NewTab.Search redirect domain
Domain nautilus-notes[.]com Nautilus Search redirect domain
Domain earthapp[.]net Earth extension redirect domain (infospace broker)
Domain wanderlustar[.]com Wanderlustar redirect domain
Domain services.templatesearchsvc[.]org Template Search redirect domain
Domain earth3d[.]net Earth 3D redirect domain (infospace broker)
Domain myfocalfind[.]com My Focal Find redirect domain
Domain greatstartapp[.]com Great Start redirect domain (becovi broker)
Domain freshfruittab[.]com Fresh Fruit Search redirect domain
Domain viewmenuprices[.]com View Menu with Prices redirect domain (infospace broker)
Domain searchtoggler[.]com Search Toggler operator domain
Domain loginonlineapp[.]com Easy Login redirect domain (infospace broker)
Domain seek.searchthatweb[.]com SearchThatWeb redirect domain
Domain search.freshysearchapi[.]net Freshy Search redirect domain (trp broker)
Domain myvideolibrary[.]info Video Search Extension redirect domain
Domain bestfreemaps[.]com Get Maps & Driving Directions + Satelliten Earth redirect domain
Domain searchanything[.]co Search Anything redirect domain (mnet broker)
Domain oasrchrdr[.]com Surfer Search redirect domain (fc broker)
Domain s.fusebasesearch[.]com Fusebase Search redirect domain (dcola broker)
Domain worthathousandwords[.]com Search Toggler contact email domain
Extension ID hohedjmdoemgcpgdapepfhnilbedldnm PerfecTab Search (Chrome Extension ID)
Extension ID keadechokmcohlcampccppbjjeabghcd Quick Search Tool (Chrome Extension ID)
Extension ID epdmngmgidehpmhjamdjcaecpligmcfh Better Search (Chrome Extension ID)
Extension ID pookachmhghnpgjhebhilcidgdphdlhi NewTab.Search (Chrome Extension ID)
Extension ID flcaigefphghbcgbmfngbfdgipdflfpn Nautilus Search (Chrome Extension ID)
Extension ID hnfdneofpohlkoeljnmkdocokcdk jiaa Earth (Chrome Extension ID)
Extension ID bgliakflmjnofiolfmnbncdmgfnibgnj Wanderlustar (Chrome Extension ID)
Extension ID cnkcgoiimpncbonlilkekbigfhchcbgb Template Search (Chrome Extension ID)
Extension ID kbobdmmjbaljcombpliahadgoafgohcd Earth 3D (Chrome Extension ID)
Extension ID eeejfmalgedffijdepcdmgemfnadjefe My Focal Find (Chrome Extension ID)
Extension ID mccmkaicbneobeclkbloeoopcfeipmio Great Start (Chrome Extension ID)
Extension ID jeookppofphgjnhjkifeejcmjbpiogka Fresh Fruit Search (Chrome Extension ID)
Extension ID ijbmkpeacbkgpfkomjbionjgdhbmlpfp View Menu with Prices (Chrome Extension ID)
Extension ID hodgcolihbmeagfcfpdfpnapfflmpbkb Search Toggler (Chrome Extension ID)
Extension ID cpmjnpalighpdecgankobogpcmbceaig Easy Login (Chrome Extension ID)
Extension ID akimdaijebpdfo jiohhimbebkdigkccj SearchThatWeb (Chrome Extension ID)
Extension ID oikgbpcmdphfkhplgkfngjilemlo lann Freshy Search (Chrome Extension ID)
Extension ID efakcomgmimcekdejnoafmmbgnpdhdfm Video Search Extension (Chrome Extension ID)
Extension ID gmapdckphdmbafmmcfoahhgoogdjeell Get Maps & Driving Directions (Chrome Extension ID)
Extension ID odafhekandnacimkenmaagnoemnpaakk Search Anything (Chrome Extension ID)
Extension ID jgoihmjphghpnjedflgemmhjdaogimad Satelliten Earth (Chrome Extension ID)
Extension ID dllhnjhfilgcjopkgdekmdmfilpfceig Surfer Search (Chrome ID)
Extension ID ododhdcefemfdbnidbeipjpjaehadjen Fusebase Search (Chrome Extension ID)
URL Parameter hspart=trp Broker tracking parameter — unknown operator
URL Parameter hspart=infospace Broker tracking parameter — System1
URL Parameter hspart=flowsurf Broker tracking parameter — unknown operator
URL Parameter hspart=adk Broker tracking parameter — unknown operator
URL Parameter hspart=becovi Broker tracking parameter — Becovi Ltd, Dublin
URL Parameter hspart=imageadvan Broker tracking parameter — unknown operator
URL Parameter hspart=mnet Broker tracking parameter — unknown operator
URL Parameter hspart=fc Broker tracking parameter — unknown operator
URL Parameter hspart=dcola Broker tracking parameter — unknown operator
Email edgarlife1980[@]gmail[.]com Publisher account for Earth 3D extension

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

phishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

PromptSnatcher Ad Blocker Extensions Steal AI Chats

Next Post

China-Nexus Hackers Exploit Backdoored PAM Modules for Credential Theft

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
GitHub Expands Malware Detection to 8 Package Registries
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us