Security researchers identified the 'PolinRider' campaign on 4 July 2026, which utilized malicious Chrome extensions to harvest data from developers and cryptocurrency users. This discovery coincides with reports on the 'ConsentFix' technique, a browser-based attack that hijacks Microsoft 365 accounts by abusing OAuth flows, and the removal of a fake 'Perplexity AI' extension that intercepted search queries and address bar keystrokes. These findings highlight ongoing threats despite Google's recent policy crackdown on unauthorized data collection.
- PolinRider Campaign Discovery: On 4 July 2026, researchers linked the 'PolinRider' campaign to North Korean hackers who published 108 malicious packages and extensions, including a Chrome extension designed to deliver BeaverTail malware.
- Fake Perplexity AI Extension Removal: Reports on 3 July 2026 detailed the removal of 'Search for perplexity ai' (ID: flkebkiofojicogddingbdmcmkpbplcd), which was found to be intercepting all search traffic and keystrokes from the browser's address bar.
- ConsentFix Browser Attack: A security advisory on 3 July 2026 highlighted 'ConsentFix', a browser-native phishing method that hijacks Microsoft 365 session tokens by abusing legitimate OAuth flows without requiring passwords.
- Chrome Web Store Policy Enforcement: Google has set a deadline of 1 August 2026 for developers to comply with new rules that strictly limit data collection to the extension's single disclosed purpose and ban AI-jailbreaking tools. Calendar file (.ics) Chrome Web Store Policy Enforcement Deadline August 1, 2026