A featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network
While analyzing featured extensions on our beloved chrome web store I landed on Planet ( kadaohckdkghfaclhjmkmplebcdcnfnp ), Featured, 2M users, publisher FREE VPN PLANET SRL . The extensions has a 0-byte background.js with zero permissions. The whole mechanism is one chrome_settings_overrides provider, so nothing shows up statically. It's all server-side. Declared provider is planet- [.]com . Tracing: planet- [.]com/ /?q= 301 → sstmaster[.]com/edge/PN1021?q= 302 → nextgeeker[.]com/B151001.php?q=&src=PN1021 nextgeeker[.]com is flagged as a browser hijacker by multiple vendors (pcrisk, gridinsoft, others). PN1021 is the affiliate subid linking the extension's traffic to that network. The listing discloses none of the hops and says only that results come from Google (the final page is a Google CSE render). Same publisher ships a ~1M-user VPN extension and a few others. Still tracing those, not going to characterize them until I have. Report: submitted by /u/Huge-Skirt-6990 [link] [ ]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
