A few possibilities I can think of:
- Trying to figure out commonly-mistyped domain names in order to buy them for ad placement.
- Trying to obtain confidential information that's accidentally pasted into the address bar.
- Trying to obtain internal domain names that someone tries to access while disconnected from a VPN or just physically outside the office.
- (If the extension could catch all non-existent domain errors, not just ones from typing in the address bar) attempting to find abandoned domains that are still referenced by JavaScript and whatnot in order to buy them. This could potentially be used to inject content (probably ads) into the systems that still reference those domains.
- Legitimate research into how users mistype domain names, maybe to figure out how to think of names that are less likely to be mistyped.
I don't know offhand if modern browsers also do DNS lookups as the user is typing characters into the address bar, or just do Google/Bing/whatever queries as the user is typing. I know they do the latter (i.e. typing 'news.ycombinator.com' into the address bar will send queries for 'n', 'ne', 'new', 'news', and so on to the search engine), but I don't know if they're also still doing DNS lookups at each step as well. If they are, and the extension could capture all of those, then that could be an interesting way to collect users' search queries.