Chrome Extension 'Planet Search' Routes Queries to Hijacker Network
Article Content
- •The 'Planet Search' extension has 2 million installs and routes queries to a hijacker network.
- •It features a 0-byte background.js, indicating server-side functionality without user permissions.
- •The publisher, FREE VPN PLANET SRL, also has a VPN extension with around 1 million users.
The Chrome extension 'Planet Search', with 2 million installs, has been found to route user queries to the hijacker network nextgeeker.com. The extension, published by FREE VPN PLANET SRL, features a 0-byte background.js and zero permissions, indicating that its functionality is entirely server-side. Tracing reveals that user queries are redirected through multiple hops, ultimately leading to a page flagged as a browser hijacker by several security vendors. The extension's listing falsely claims that results are sourced from Google. The same publisher also offers a VPN extension with approximately 1 million users. Ongoing investigations are being conducted to assess the full scope of the publisher's other extensions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…