SearchJack: 23 Malicious Chrome Extensions Hijack Search Queries via chrome_settings_overrides (Yahoo Affiliate Monetization) — Threadlinqs Intelligence
As of 2026-06-15, SearchJack: 23 Malicious Chrome Extensions Hijack Search Queries via chrome_settings_overrides (Yahoo Affiliate Monetization) is a high-severity malware threat attributed to SearchJack operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 52 indicators of compromise.
Threat ID: TL-2026-0812 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: SearchJack operators · FINANCIAL
SearchJack is a coordinated campaign of 23 deceptive Chrome extensions (~758,000 combined installs) that abuse the chrome_settings_overrides manifest key to seize the browser's default search engine,
MalExt Sentry researchers identified a structured campaign, dubbed SearchJack, of 23 deceptive Chrome Web Store extensions that collectively reached approximately 758,000 installs. Each extension advertises a benign purpose — satellite imagery (Earth, Earth 3D, Satelliten Earth), productivity new-tab pages (PerfecTab Search, NewTab.Search, Great Start), maps (Get Maps & Driving Directions, Best Free Maps), or generic search tools — while its actual function is to monetize the victim's search traffic.
The core technique is abuse of Chrome's built-in `chrome_settings_overrides` manifest key with `is_default: true`, which overrides the browser's default search engine to point at an operator-controlled relay domain. The majority of the extensions are 'shell' or manifest-only wrappers: they contain little beyond the manifest — no requested permissions, no background script, and no content scripts — which lets them pass cursory review and minimizes static-analysis surface. When the user performs a search, the query is first sent to the relay domain (e.g. myperfecttab.com/search/, earthapp.net/admin/public/link), which records it and then 302-redirects through Yahoo Hosted Search to render results that look entirely normal to the victim.
Monetization runs through Yahoo's search affiliate program. The relay operator (broker) is identified by the `hspart` parameter embedded in the final Yahoo redirect URL and earns revenue-sharing payments on each search. MalExt Sentry traced at least eight distinct broker identifiers — trp, infospace (publicly System1), flowsurf, adk, becovi (Becovi Ltd, Dublin), imageadvan, mnet, fc, and dcola — across 22 publishers. System1/infospace-affiliated extensions consistently route through `/admin/public/link` endpoints (earth3d.net, earthapp.net, loginonlineapp.com).
The campaign sits at the boundary between aggressive adware/PUP and genuine security risk. Data collection is real: the Nautilus Search store listing claims it never tracks searches or collects personal data, yet its linked privacy policy explicitly discloses collection of IP addresses, search queries, and device identifiers. More importantly, because the operators fully control the relay tier between the browser and the search results, they can change the destination at any time — switching from benign Yahoo results to phishing landing pages or malicious downloads — entirely server-side and without pushing any new extension code, which is why MalExt Sentry elevated SearchJack above ordinary adware. One outlier, Search Toggler, is not a pure shell: it injects routing logic at runtime via chrome.declarativeNetRequest.updateDynamicRules() in background.js, so its real behavior is invisible to static manifest inspection.
Weaknesses (CWE)
CWE-451, CWE-829, CWE-359
Target sectors: consumer, general public, enterprise endpoints
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 52 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1585, T1608, T1204, T1176, T1036, T1656, T1027, T1185, T1217