A featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network
The Chrome extension "Planet Search" with approximately 2 million installs is a search hijacker that routes all user queries through a chain of undisclosed redirects ending at nextgeeker.com, a domain flagged by multiple vendors as a browser hijacker. The extension declares itself as a default search provider but does not disclose the intermediate redirects or the affiliate monetization relationship. The extension's code is minimal and does not reveal this behavior, as the redirect logic is entirely server-side. Users receive standard Google Custom Search results, but their queries transit through third-party domains that may observe search data. The extension is published by FREE VPN PLANET SRL, which also offers other extensions under investigation. The threat was reported to the Chrome Web Store and Google Safe Browsing on 2026-07-25.
AI Analysis
Technical Summary
The Chrome extension "Planet Search" (ID: kadaohckdkghfaclhjmkmplebcdcnfnp) is a deceptive search hijacker that overrides the default search engine via the chrome_settings_overrides manifest key. Instead of directly querying Google, all search queries are routed through a redirect chain: planet-search.com (declared provider) issues a 301 redirect to sstmaster.com/edge/PN1021, which then issues a 302 redirect to nextgeeker.com/B151001.php with an affiliate subid (PN1021). Nextgeeker.com is flagged by multiple anti-malware vendors as a browser hijacker known for harvesting user data and delivering fake search results. The extension's CRX package contains a 0-byte background script and no host permissions, making the hijacking behavior invisible to static analysis. The listing misleadingly claims results come from Google and requests zero permissions, hiding the monetization and data exposure risks. The redirect chain is geo-aware and does not filter user agents, indicating broad impact. The publisher also distributes other extensions with significant user bases, currently under further review. The issue was reported to Google and relevant security feeds on 2026-07-25.
Potential Impact
Users of the Planet Search Chrome extension have their search queries silently routed through third-party domains, exposing their search terms to these intermediaries without disclosure. The final search results are standard Google Custom Search results, providing no added user benefit. The affiliate subid in the redirect chain indicates undisclosed monetization. The nextgeeker.com domain is recognized as a browser hijacker that may collect search history, visited sites, location, and IP address. This behavior compromises user privacy and trust. There is no indication of direct code execution or system compromise, but the data exposure and deceptive behavior constitute a medium-severity privacy and security risk.
Mitigation Recommendations
As of the report date, no official patch or fix is indicated. The extension has been reported to the Chrome Web Store and Google Safe Browsing for removal. Users should uninstall the Planet Search extension immediately to prevent further query hijacking and data exposure. Security teams should monitor for this extension in their environments and block or remove it where found. Since the hijacking is implemented server-side, static analysis of the extension package will not reveal the behavior. No vendor advisory or official fix is currently available; check the Chrome Web Store and Google Safe Browsing feeds for updates on removal or remediation.
A featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network
Description
The Chrome extension "Planet Search" with approximately 2 million installs is a search hijacker that routes all user queries through a chain of undisclosed redirects ending at nextgeeker.com, a domain flagged by multiple vendors as a browser hijacker. The extension declares itself as a default search provider but does not disclose the intermediate redirects or the affiliate monetization relationship. The extension's code is minimal and does not reveal this behavior, as the redirect logic is entirely server-side. Users receive standard Google Custom Search results, but their queries transit through third-party domains that may observe search data. The extension is published by FREE VPN PLANET SRL, which also offers other extensions under investigation. The threat was reported to the Chrome Web Store and Google Safe Browsing on 2026-07-25.
Reddit Discussion
While analyzing featured extensions on our beloved chrome web store I landed on Planet Search (kadaohckdkghfaclhjmkmplebcdcnfnp), Featured, 2M users, publisher FREE VPN PLANET SRL.
The extensions has a 0-byte background.js with zero permissions.
The whole mechanism is one chrome_settings_overrides search provider, so nothing shows up statically. It's all server-side.
Declared provider is planet-search[.]com. Tracing:
planet-search[.]com/search/?q= 301 → sstmaster[.]com/edge/PN1021?q= 302 → nextgeeker[.]com/B151001.php?q=&src=PN1021 nextgeeker[.]com is flagged as a browser hijacker by multiple vendors (pcrisk, gridinsoft, others).
PN1021 is the affiliate subid linking the extension's traffic to that network. The listing discloses none of the hops and says only that results come from Google (the final page is a Google CSE render).
Same publisher ships a ~1M-user VPN extension and a few others. Still tracing those, not going to characterize them until I have.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Chrome extension "Planet Search" (ID: kadaohckdkghfaclhjmkmplebcdcnfnp) is a deceptive search hijacker that overrides the default search engine via the chrome_settings_overrides manifest key. Instead of directly querying Google, all search queries are routed through a redirect chain: planet-search.com (declared provider) issues a 301 redirect to sstmaster.com/edge/PN1021, which then issues a 302 redirect to nextgeeker.com/B151001.php with an affiliate subid (PN1021). Nextgeeker.com is flagged by multiple anti-malware vendors as a browser hijacker known for harvesting user data and delivering fake search results. The extension's CRX package contains a 0-byte background script and no host permissions, making the hijacking behavior invisible to static analysis. The listing misleadingly claims results come from Google and requests zero permissions, hiding the monetization and data exposure risks. The redirect chain is geo-aware and does not filter user agents, indicating broad impact. The publisher also distributes other extensions with significant user bases, currently under further review. The issue was reported to Google and relevant security feeds on 2026-07-25.
Potential Impact
Users of the Planet Search Chrome extension have their search queries silently routed through third-party domains, exposing their search terms to these intermediaries without disclosure. The final search results are standard Google Custom Search results, providing no added user benefit. The affiliate subid in the redirect chain indicates undisclosed monetization. The nextgeeker.com domain is recognized as a browser hijacker that may collect search history, visited sites, location, and IP address. This behavior compromises user privacy and trust. There is no indication of direct code execution or system compromise, but the data exposure and deceptive behavior constitute a medium-severity privacy and security risk.
Mitigation Recommendations
As of the report date, no official patch or fix is indicated. The extension has been reported to the Chrome Web Store and Google Safe Browsing for removal. Users should uninstall the Planet Search extension immediately to prevent further query hijacking and data exposure. Security teams should monitor for this extension in their environments and block or remove it where found. Since the hijacking is implemented server-side, static analysis of the extension package will not reveal the behavior. No vendor advisory or official fix is currently available; check the Chrome Web Store and Google Safe Browsing feeds for updates on removal or remediation.
Technical Details
- Source Type
- Subreddit
- netsec
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a64954c9c2644c7f83c439e
Added to database: 07/25/2026, 10:51:56 UTC
Last enriched: 07/25/2026, 10:52:10 UTC
Last updated: 07/26/2026, 01:22:02 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.