Malicious Chrome and Edge extensions found stealing crypto and browser data
Google Chrome and Microsoft Edge users fell victim to a coordinated campaign involving malicious Chrome extensions that deployed a sophisticated malware framework designed to steal cryptocurrency, sensitive browser data, and user credentials. The operation, uncovered by application security company Socket, reveals how attackers compromised legitimate extensions to distribute malware modules capable of injecting ClickFix lures and harvesting personal information.
How the malicious Chrome extensions operated
The campaign involved 16 distinct malware modules, each serving specific purposes and engineered to be highly extensible. According to Socket’s investigation, the operation may have been active since early 2024. What made this campaign particularly insidious was that five of the malicious Chrome extensions were acquired from their original creators and then injected with malware through automatic updates—meaning users initially downloaded legitimate tools before they turned dangerous.

One notable example is “Enable Right Click & Copy — Smart Unlock + OCR,” the only extension available on both Chrome and Edge during the campaign. When it turned malicious, it had accumulated at least 70,000 users on Chrome and 10,000 on Edge. Google removed the extension from its marketplace relatively quickly, but the Edge version remained available at the time Socket published its findings.
Once installed, the malware established an encrypted WebSocket connection to command-and-control servers, downloaded JavaScript modules, stripped Content Security Policy headers from websites, and injected malicious scripts through hidden HTML elements. Socket identified modules capable of stealing cryptocurrency wallets, extracting browser history, harvesting credentials, and deploying ClickFix social engineering lures.
What users and defenders should do now
Anyone who installed these malicious Chrome extensions should assume their credentials have been compromised and change all login passwords immediately. Cryptocurrency holders affected by the campaign are urged to move their assets to a newly created wallet as soon as possible. At the time of Socket’s report, none of the malicious extensions remained in the Chrome Web Store, though the company warned that the framework may contain additional undiscovered modules.
This incident underscores a broader pattern of supply-chain attacks targeting browser extensions. As covered earlier, CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks highlighted how critical vulnerabilities in development tools can be weaponized at scale. Similarly, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions demonstrated how attackers exploit trusted platforms to compromise user sessions and steal sensitive data. Socket’s full report includes the complete list of affected extension IDs and C2 communication domains to help security teams identify and block related threats.
المصدر: BleepingComputer