Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Planet Search chrome extension with 2 millions installs routing traffic throught malicious domain

0
Medium
Published: 07/26/2026 (07/26/2026, 07:02:24 UTC)
Source: Reddit BlueTeam

Description

The Planet Search Chrome extension, with approximately 2 million installs, has been observed routing user search traffic through a chain of malicious domains. The extension itself has a minimal local footprint with no permissions and a zero-byte background script, relying on server-side mechanisms to override Chrome's default search provider. The traffic is redirected through domains flagged as browser hijackers by multiple security vendors. The publisher also offers other extensions, including a VPN extension with around 1 million users, which are under further investigation.

Reddit Discussion

r/blueteamsec·posted by u/Huge-Skirt-6990
00

While analyzing featured extensions on our beloved chrome web store I landed on Planet Search (`kadaohckdkghfaclhjmkmplebcdcnfnp`),

Featured, 2M users, publisher FREE VPN PLANET SRL.

https://chromewebstore.google.com/detail/planet-search/kadaohckdkghfaclhjmkmplebcdcnfnp

The extensions has a 0-byte background.js with zero permissions.

The whole mechanism is one \`chrome\_settings\_overrides\` search provider, so nothing shows up statically. It's all server-side.

Declared provider is planet-search[.]com

Tracing:

planet-search[.]com/search/?q= 301 → sstmaster[.]com/edge/PN1021?q= 302 → nextgeeker[.]com/B151001.php?q=&src=PN1021

nextgeeker[.]com is flagged as a browser hijacker by multiple vendors (pcrisk, gridinsoft, others).

Same publisher ships a ~1M-user VPN extension and a few others. Still tracing those, not going to characterize them until I have.

Report: https://malext.io/reports/RoguePlanet

Also discussed in: r/Malware

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/26/2026, 07:07:08 UTC

Technical Analysis

Planet Search is a Chrome extension that overrides the default search provider to route user search queries through a series of redirects involving malicious domains. The extension's local code is minimal and does not request permissions, indicating that the redirection logic is controlled server-side. The final redirect leads to domains identified as browser hijackers by multiple antivirus vendors. This behavior can compromise user privacy and potentially expose users to unwanted content or further malicious activity. The publisher, FREE VPN PLANET SRL, also distributes other extensions, including a VPN extension with a large user base, which are currently being analyzed for similar behavior.

Potential Impact

Users of the Planet Search extension are subject to their search traffic being routed through malicious domains, which can lead to privacy violations, exposure to unwanted or harmful content, and potential further compromise. The redirection through known browser hijacker domains indicates a risk of unwanted tracking, manipulation of search results, and possible exposure to malware or phishing. The large user base (2 million installs) increases the scale of potential impact.

Mitigation Recommendations

No official patch or remediation from the vendor is indicated. Users should remove the Planet Search extension from their Chrome browsers immediately to prevent further traffic redirection through malicious domains. Removal instructions are available via the Chrome extensions management interface. Security teams should monitor for the presence of this extension in their environments and advise users accordingly. Since the extension relies on server-side control, blocking the identified malicious domains at the network level may provide additional mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a65b2169c2644c7f844996d

Added to database: 07/26/2026, 07:07:02 UTC

Last enriched: 07/26/2026, 07:07:08 UTC

Last updated: 07/26/2026, 19:52:02 UTC

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses