Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures.

Researchers say all 19 malicious modules uncovered in the campaign serve distinct purposes and are designed to be “highly extensible.”

The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024.

Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware.

According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically.

One example is the “Enable Right Click & Copy — Smart Unlock + OCR” extension, which had a Chrome user base of at least 70,000 when it turned malicious. The number of installs on Edge was 10,000 at the time.

Google caught the threat early and removed the extension from its add-ons marketplace, but at the time of Socket publishing its report, the Edge version remained available.

Once installed, the malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from every website visited, and injects malicious scripts into websites through hidden HTML elements.

Socket observed malware modules with the following capabilities:

Socket warns that the malicious framework may have more modules and that as the malware evolves over time, new payloads are expected to be deployed.

At the time of publishing, none of the malicious extensions are available in the Chrome Web Store.

Socket’s report provides the full list of extension IDs uncovered in the campaign along with the domains used for C2 communication.

Users who had any of the extensions installed should assume that their credentials have been compromised and change their login passwords.

Cryptocurrency holders potentially impacted by this campaign are recommended to move their assets to a newly created wallet as soon as possible.

Update [August 30]: Article edited to include the full list of malicious extensions discovered by Socket.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Fake Perplexity extension on Chrome Web Store tracked searches

Google Chrome may soon block New Tab hijacker extensions by default

Adobe Chrome extension flaw let sites access private WhatsApp chats

New OkoBot framework deploys 20 payloads to steal data, crypto

lousy reporting. takes forever to get to the point, doesnt even advise what extensions. reports lots of unnecessary info while leaving out important tidbits.

68-year-old imprisoned after making $1.3 million by pirating IPTV services

Anthropic is cutting Claude Code’s current weekly limits by 17%

McKesson discloses breach after ShinyHunters claims patient data theft

Learn how ESET MDR can enhance your organization’s security posture

AI-driven vulnerability discovery is accelerating. See how Action1 helps remediation keep pace.

Discover why encryption and key management are critical for modern business.

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

Overdue a password health-check? Audit your Active Directory for free

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.