Skip to content
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
Subscribe
Close

Search

nextbyte.live nextbyte.live
nextbyte.live nextbyte.live
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • gadgets
  • ai
  • cybersecurity
  • web
  • crypto
  • tech
  • hardware
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Malicious Chrome and Edge extensions found stealing crypto and browser data
cybersecurity

Malicious Chrome and Edge extensions found stealing crypto and browser data

By abde el aziz
August 30, 2026 2 Min Read
0

Google Chrome and Microsoft Edge users fell victim to a coordinated campaign involving malicious Chrome extensions that deployed a sophisticated malware framework designed to steal cryptocurrency, sensitive browser data, and user credentials. The operation, uncovered by application security company Socket, reveals how attackers compromised legitimate extensions to distribute malware modules capable of injecting ClickFix lures and harvesting personal information.

Table of Contents

  • How the malicious Chrome extensions operated
  • What users and defenders should do now

How the malicious Chrome extensions operated

The campaign involved 16 distinct malware modules, each serving specific purposes and engineered to be highly extensible. According to Socket’s investigation, the operation may have been active since early 2024. What made this campaign particularly insidious was that five of the malicious Chrome extensions were acquired from their original creators and then injected with malware through automatic updates—meaning users initially downloaded legitimate tools before they turned dangerous.

Malicious Chrome and Edge extensions found stealing crypto and browser data

One notable example is “Enable Right Click & Copy — Smart Unlock + OCR,” the only extension available on both Chrome and Edge during the campaign. When it turned malicious, it had accumulated at least 70,000 users on Chrome and 10,000 on Edge. Google removed the extension from its marketplace relatively quickly, but the Edge version remained available at the time Socket published its findings.

Once installed, the malware established an encrypted WebSocket connection to command-and-control servers, downloaded JavaScript modules, stripped Content Security Policy headers from websites, and injected malicious scripts through hidden HTML elements. Socket identified modules capable of stealing cryptocurrency wallets, extracting browser history, harvesting credentials, and deploying ClickFix social engineering lures.

What users and defenders should do now

Anyone who installed these malicious Chrome extensions should assume their credentials have been compromised and change all login passwords immediately. Cryptocurrency holders affected by the campaign are urged to move their assets to a newly created wallet as soon as possible. At the time of Socket’s report, none of the malicious extensions remained in the Chrome Web Store, though the company warned that the framework may contain additional undiscovered modules.

This incident underscores a broader pattern of supply-chain attacks targeting browser extensions. As covered earlier, CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks highlighted how critical vulnerabilities in development tools can be weaponized at scale. Similarly, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how attackers exploit trusted platforms to compromise user sessions and steal sensitive data. Socket’s full report includes the complete list of affected extension IDs and C2 communication domains to help security teams identify and block related threats.

المصدر: BleepingComputer

Author

abde el aziz

Follow Me
Other Articles
Why Samsung's Predictable Galaxy Updates Are Winning the RAM Shortage Era
Previous

Why Samsung’s Predictable Galaxy Updates Are Winning the RAM Shortage Era

Anthropic warns infostealer malware is hijacking Claude user sessions
Next

Anthropic warns infostealer malware is hijacking Claude user sessions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • New BambooToken Malware Uses MQTT to Control Windows and Linux Systems
  • Apple rolls out iOS 27 with Siri AI beta
  • Is the GTA 6 Ultimate Edition worth the extra cost?
  • Apple CEO discusses why iPhone Duo foldable arrived after Android rivals
  • Google launches Gemini app for Windows

Recent Comments

  1. New BambooToken Malware Uses MQTT to Control Windows and Linux Systems on CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks
  2. Apple rolls out iOS 27 with Siri AI beta on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  3. Is the GTA 6 Ultimate Edition worth the extra cost? on Samsung Galaxy S26 FE vs S25 FE: Explaining the $50 Price Increase
  4. Apple CEO discusses why iPhone Duo foldable arrived after Android rivals on The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  5. Google launches Gemini app for Windows on Google AI Mode adds flight price tracking and hotel booking tools

Archives

  • September 2026
  • August 2026

Categories

  • ai
  • crypto
  • cybersecurity
  • gadgets
  • hardware
  • tech
  • web
Copyright 2026 — nextbyte.live. All rights reserved. Blogsy WordPress Theme