Planet Search chrome extension with 2 millions installs routing traffic throught malicious domain
The Planet Search Chrome extension, with approximately 2 million installs, has been observed routing user search traffic through a chain of malicious domains. The extension itself has a minimal local footprint with no permissions and a zero-byte background script, relying on server-side mechanisms to override Chrome's default search provider. The traffic is redirected through domains flagged as browser hijackers by multiple security vendors. The publisher also offers other extensions, including a VPN extension with around 1 million users, which are under further investigation.
AI Analysis
Technical Summary
Planet Search is a Chrome extension that overrides the default search provider to route user search queries through a series of redirects involving malicious domains. The extension's local code is minimal and does not request permissions, indicating that the redirection logic is controlled server-side. The final redirect leads to domains identified as browser hijackers by multiple antivirus vendors. This behavior can compromise user privacy and potentially expose users to unwanted content or further malicious activity. The publisher, FREE VPN PLANET SRL, also distributes other extensions, including a VPN extension with a large user base, which are currently being analyzed for similar behavior.
Potential Impact
Users of the Planet Search extension are subject to their search traffic being routed through malicious domains, which can lead to privacy violations, exposure to unwanted or harmful content, and potential further compromise. The redirection through known browser hijacker domains indicates a risk of unwanted tracking, manipulation of search results, and possible exposure to malware or phishing. The large user base (2 million installs) increases the scale of potential impact.
Mitigation Recommendations
No official patch or remediation from the vendor is indicated. Users should remove the Planet Search extension from their Chrome browsers immediately to prevent further traffic redirection through malicious domains. Removal instructions are available via the Chrome extensions management interface. Security teams should monitor for the presence of this extension in their environments and advise users accordingly. Since the extension relies on server-side control, blocking the identified malicious domains at the network level may provide additional mitigation.
Planet Search chrome extension with 2 millions installs routing traffic throught malicious domain
Description
The Planet Search Chrome extension, with approximately 2 million installs, has been observed routing user search traffic through a chain of malicious domains. The extension itself has a minimal local footprint with no permissions and a zero-byte background script, relying on server-side mechanisms to override Chrome's default search provider. The traffic is redirected through domains flagged as browser hijackers by multiple security vendors. The publisher also offers other extensions, including a VPN extension with around 1 million users, which are under further investigation.
Reddit Discussion
While analyzing featured extensions on our beloved chrome web store I landed on Planet Search (`kadaohckdkghfaclhjmkmplebcdcnfnp`),
Featured, 2M users, publisher FREE VPN PLANET SRL.
https://chromewebstore.google.com/detail/planet-search/kadaohckdkghfaclhjmkmplebcdcnfnp
The extensions has a 0-byte background.js with zero permissions.
The whole mechanism is one \`chrome\_settings\_overrides\` search provider, so nothing shows up statically. It's all server-side.
Declared provider is planet-search[.]com
Tracing:
planet-search[.]com/search/?q= 301 → sstmaster[.]com/edge/PN1021?q= 302 → nextgeeker[.]com/B151001.php?q=&src=PN1021
nextgeeker[.]com is flagged as a browser hijacker by multiple vendors (pcrisk, gridinsoft, others).
Same publisher ships a ~1M-user VPN extension and a few others. Still tracing those, not going to characterize them until I have.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Planet Search is a Chrome extension that overrides the default search provider to route user search queries through a series of redirects involving malicious domains. The extension's local code is minimal and does not request permissions, indicating that the redirection logic is controlled server-side. The final redirect leads to domains identified as browser hijackers by multiple antivirus vendors. This behavior can compromise user privacy and potentially expose users to unwanted content or further malicious activity. The publisher, FREE VPN PLANET SRL, also distributes other extensions, including a VPN extension with a large user base, which are currently being analyzed for similar behavior.
Potential Impact
Users of the Planet Search extension are subject to their search traffic being routed through malicious domains, which can lead to privacy violations, exposure to unwanted or harmful content, and potential further compromise. The redirection through known browser hijacker domains indicates a risk of unwanted tracking, manipulation of search results, and possible exposure to malware or phishing. The large user base (2 million installs) increases the scale of potential impact.
Mitigation Recommendations
No official patch or remediation from the vendor is indicated. Users should remove the Planet Search extension from their Chrome browsers immediately to prevent further traffic redirection through malicious domains. Removal instructions are available via the Chrome extensions management interface. Security teams should monitor for the presence of this extension in their environments and advise users accordingly. Since the extension relies on server-side control, blocking the identified malicious domains at the network level may provide additional mitigation.
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a65b2169c2644c7f844996d
Added to database: 07/26/2026, 07:07:02 UTC
Last enriched: 07/26/2026, 07:07:08 UTC
Last updated: 07/26/2026, 19:52:02 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.