MalExt Sentry ← Report Library
2026-06-09 Adware tracking Search Hijacking

SearchJack: How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches

Campaign Overview

FieldValue
Campaign NameSearchJack
Extensions Identified23
Unique Publishers22
Total Affected Users~758,000
Brokers Identified8
Primary MonetizationHosted Search Affiliate (Yahoo, multi-network)
Date of AnalysisJune 09, 2026

SearchJack is a campaign of 23 deceptive Chrome browser extensions that silently override users' default search engines and route queries through monetization middleware before delivering results. Each extension presents a different advertised purpose - satellite imagery, productivity tools, news readers, maps - while the actual business is search affiliate revenue. The campaign spans at least 8 distinct monetization brokers and ~758,000 affected users.

Data for this report was collected using the MalExt Sentry automated scanner. We continuously monitor browser extension stores and flag suspicious items based on specific keywords in their descriptions and metadata. For the SearchJack campaign, our scanner specifically identified extensions abusing the chrome_settings_overrides key in their manifest files to hijack user search settings.


Broker Infrastructure

The broker is identified by the hspart parameter in the final Yahoo redirect URL. The broker layer is the structural enabler of this campaign - individual extensions are disposable shells. The broker relationship, Yahoo partner account, and revenue infrastructure persist regardless of which extensions are active.

hspartBrokerExtensionsEst. Installs
trpUnknown3~160K
infospaceSystem1 (public)6~117K
flowsurfUnknown1100K
adkUnknown1100K
-Unknown6~178K
becoviBecovi Ltd, Dublin130K
imageadvanUnknown110K
mnetUnknown13K
fcUnknown12K
dcolaUnknown1490

Full Extension Corpus

Extension IDNamePublisherInstallsRatingFirst PublishedLast Updated
hohedjmdoemgcpgdapepfhnilbedldnmPerfecTab SearchKinner Lake Ltd.100K4.5 (4)2024-09-182024-09-18
keadechokmcohlcampccppbjjeabghcdQuick Search Toolquicksearchtool[.]com100K5 (2)2021-09-292024-04-02
epdmngmgidehpmhjamdjcaecpligmcfhBetter SearchBetter Search100K4.3 (350)2024-11-072026-03-20
pookachmhghnpgjhebhilcidgdphdlhiNewTab. SearchBonjour70K4.5 (83)2018-07-112024-12-18
flcaigefphghbcgbmfngbfdgipdflfpnNautilus Searchnautilusnotesapp50K-2025-01-312025-01-31
hnfdneofpohlkoeljnmkdocokcdkjiaaEarthEarth50K1 (1)2025-03-292026-01-23
bgliakflmjnofiolfmnbncdmgfnibgnjWanderlustarWanderlustar50K5 (1)2022-11-042024-10-28
cnkcgoiimpncbonlilkekbigfhchcbgbTemplate SearchTemplate Search50K2.3 (3)2023-03-282025-02-02
kbobdmmjbaljcombpliahadgoafgohcdEarth 3DEarth 3D40K1 (2)2025-07-122025-07-12
eeejfmalgedffijdepcdmgemfnadjefeMy Focal Findreedd686840K1 (1)2021-07-162024-05-23
mccmkaicbneobeclkbloeoopcfeipmioGreat Startgreatstartlab30K-2024-09-182024-09-18
jeookppofphgjnhjkifeejcmjbpiogkaFresh Fruit Searchwallacenathan33010K1 (1)2021-05-232024-05-28
ijbmkpeacbkgpfkomjbionjgdhbmlpfpView Menu with PricesMenuswithPrices10K-2026-01-292026-01-29
hodgcolihbmeagfcfpdfpnapfflmpbkbSearch Toggler-10K-2025-05-212025-05-21
cpmjnpalighpdecgankobogpcmbceaigEasy LoginEasy Login10K2.5 (2)2025-07-082025-08-21
akimdaijebpdfojiohhimbebkdigkccjSearchThatWebsearchthatweb.extension10K4.9 (31)2023-06-222024-05-30
oikgbpcmdphfkhplgkfngjilemlolannFreshy SearchFreshy10K3.5 (2)2022-01-282024-06-12
efakcomgmimcekdejnoafmmbgnpdhdfmVideo Search ExtensionAlice Carrol6K3.3 (3)2020-11-042025-10-09
gmapdckphdmbafmmcfoahhgoogdjeellGet Maps & Driving DirectionsQwerPDF5K3.7 (3)2022-10-202025-04-23
odafhekandnacimkenmaagnoemnpaakkSearch AnythingSearch Anything3K3.7 (3)2023-05-092024-03-14
jgoihmjphghpnjedflgemmhjdaogimadSatelliten Earthdy1[.]com2K-2025-04-262025-05-15
dllhnjhfilgcjopkgdekmdmfilpfceigSurfer Searchsurfersearchext2K4.6 (5)2025-04-102025-07-31
ododhdcefemfdbnidbeipjpjaehadjenFusebase SearchNimbus Web Inc4904.2 (609)2013-12-212026-01-08

Search URLs & Broker Attribution

Extension IDNameSearch URLhsparthsimp
hohedjmdoemgcpgdapepfhnilbedldnmPerfecTab Searchhxxps://myperfecttab[.]com/search/?q={searchTerms}flowsurfyhs-perfecttab2
keadechokmcohlcampccppbjjeabghcdQuick Search Toolhxxps://query.quicksearchtool[.]com/s?query={searchTerms}adkyhs-adk_sbnt
epdmngmgidehpmhjamdjcaecpligmcfhBetter Searchhxxps://search.getbettersearch-api[.]com/search/{searchTerms}trpyhs-001
pookachmhghnpgjhebhilcidgdphdlhiNewTab. Searchhxxps://newtab[.]club/search?q={searchTerms}--
flcaigefphghbcgbmfngbfdgipdflfpnNautilus Searchhxxps://nautilus-notes[.]com/search?q={searchTerms}--
hnfdneofpohlkoeljnmkdocokcdkjiaaEarthhxxps://earthapp[.]net/admin/public/link?q={searchTerms}infospaceyhs-earth
bgliakflmjnofiolfmnbncdmgfnibgnjWanderlustarhxxps://wanderlustar[.]com/k?source=7023.139&kw={searchTerms}--
cnkcgoiimpncbonlilkekbigfhchcbgbTemplate Searchhxxps://services.templatesearch-svc[.]org/search/{searchTerms}trpyhs-001
kbobdmmjbaljcombpliahadgoafgohcdEarth 3Dhxxps://earth3d[.]net/admin/public/link?q={searchTerms}infospaceyhs-earth
eeejfmalgedffijdepcdmgemfnadjefeMy Focal Findhxxps://myfocalfind[.]com/search?q={searchTerms}--
mccmkaicbneobeclkbloeoopcfeipmioGreat Starthxxps://greatstartapp[.]com/serp.php?v=1.0.1&id=mccmkaicbneobeclkbloeoopcfeipmio&q={searchTerms}becoviyhs-greatstart
jeookppofphgjnhjkifeejcmjbpiogkaFresh Fruit Searchhxxps://freshfruittab[.]com/search?q={searchTerms}--
ijbmkpeacbkgpfkomjbionjgdhbmlpfpView Menu with Priceshxxps://viewmenuprices[.]com/auto-suggest/search.php?q={searchTerms}infospaceyhs-mm_viewmenu
hodgcolihbmeagfcfpdfpnapfflmpbkbSearch Togglerhxxps://searchtoggler[.]com/ext/search?src=default&q={searchTerms}imageadvanyhs-imageadvan_toggler
cpmjnpalighpdecgankobogpcmbceaigEasy Loginhxxps://loginonlineapp[.]com/admin/public/link?q={searchTerms}infospaceyhs-mm_easylogin
akimdaijebpdfojiohhimbebkdigkccjSearchThatWebhxxps://seek.searchthatweb[.]com?PCSF=true&q={searchTerms}--
oikgbpcmdphfkhplgkfngjilemlolannFreshy Searchhxxps://search.freshysearch-api[.]net/search/{searchTerms}trpyhs-001
efakcomgmimcekdejnoafmmbgnpdhdfmVideo Search Extensionhxxps://myvideolibrary[.]info/search.php?q={searchTerms}--
gmapdckphdmbafmmcfoahhgoogdjeellGet Maps & Driving Directionshxxps://bestfreemaps[.]com/search-direction.php?q={searchTerms}infospaceyhs-bestfreemaps
odafhekandnacimkenmaagnoemnpaakkSearch Anythinghxxps://searchanything[.]co/search.html?q={searchTerms}&acTypeId=1mnetyhs-001
jgoihmjphghpnjedflgemmhjdaogimadSatelliten Earthhxxps://bestfreemaps[.]com/search-earth-de.php?q={searchTerms}infospaceyhs-bestfreemaps
dllhnjhfilgcjopkgdekmdmfilpfceigSurfer Searchhxxps://oasrchrdr[.]com?dgd=RD1005461&PCSF=true&q={searchTerms}fcyhs-5956
ododhdcefemfdbnidbeipjpjaehadjenFusebase Searchhxxps://s.fusebase-search[.]com/search?q={searchTerms}dcolayhs-200

Notable Extensions

Nautilus Search - Affirmative False Privacy Claims

The store description states: "We don't track your searches, collect your personal information, or store any user data." The governing privacy policy (Kinner Lake Ltd.) explicitly discloses collection of IP addresses, search queries, and technical identifiers. These two statements cannot both be true. This is not a disclosure omission - it is an affirmative false claim in the store listing, potentially actionable under GDPR and FTC frameworks.

Search Toggler - Runtime Obfuscation

Unlike other extensions in this corpus, Search Toggler implements a genuine search engine switching UI. However, all queries are routed through searchtoggler[.]com/ext/search regardless of which engine the user selects - the operator middleware is always present in the chain. The routing logic is injected at runtime via chrome.declarativeNetRequest.updateDynamicRules() in background.js and is not present in the static extension package. The static redirect-rules.json contains only a rule matching srcorg=orgdefaulttest → google[.]com, which would only trigger in a controlled test environment. The real behavior is invisible to static analysis. Additionally, three disconnected corporate identities are associated with this extension: searchtoggler[.]com (extension domain), VPP Technologies LLC (privacy policy entity), and worthathousandwords[.]com (contact email domain).

Fusebase Search - Anomalous Review Ratio

Published by Nimbus Web Inc (legitimate company, FuseBase / Nimbus Screenshot), this extension shows 609 reviews against 490 current installs - a ratio of 1.24 that is not achievable organically. This suggests review manipulation, a CWS-triggered install count reset, or extension repurposing following a policy violation. The combination of a legitimate publisher identity and search monetization behavior warrants direct outreach to Nimbus Web Inc to confirm whether this extension remains under their control.

Earth 3D - Anonymous Publisher, Fictional Corporate Identity

Published under edgarlife1980[@]gmail[.]com. The privacy policy names "Mutual Media DBA Innosoft Group, Houston TX" - an entity with no verifiable connection to the publisher account. System1/infospace profits from this traffic while publisher accountability is effectively zero.


Campaign Patterns

Shell pattern - The majority of extensions are manifest-only wrappers: chrome_settings_overrides with is_default: true, no permissions, no background script, no content scripts. Same skeleton across multiple extensions, different domain and icon.

Trojan horse pattern - A subset invests in a superficial advertised feature (satellite imagery, maps, video library) to justify installation. The feature may be partially implemented to pass store review but is not the business purpose.

Admin path pattern - System1-affiliated extensions consistently route through /admin/public/link endpoints: earth3d[.]net, earthapp[.]net, loginonlineapp[.]com. Shared backend infrastructure template across the infospace broker network.

Publisher anonymization - Brokers do not brand their extensions. The only place operator identity surfaces is the hspart parameter in the Yahoo redirect URL - invisible to ordinary users.


Summary

SearchJack is a structured campaign of 23 deceptive Chrome browser extensions silently routing approximately ~758,000 users' search queries through operator-controlled monetization middleware. The campaign spans at least 8 distinct affiliate brokers and 22 publishers across multiple jurisdictions. The common enabling infrastructure - Yahoo Hosted Search and equivalent affiliate programs - imposes insufficient publisher vetting, allowing anonymous operators to monetize user search behavior at scale. Individual extension removal is insufficient; enforcement action at the broker level is required to disrupt the underlying monetization infrastructure.

Threat Impact

Why does this matter? While this might look like simple adware, it is a real security risk. First, it is a massive privacy violation: every search a user makes is sent to anonymous third-party brokers. Second, because the operators control the web traffic, they can easily switch from showing regular search results to injecting phishing links or malicious downloads at any time—all without ever updating the extension code itself.


*Research by Jean-Marie R. (Toborrm9) | Malicious Extension Sentry Project | June 09, 2026*