Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures.
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures.
BleepingComputer
Publisher
Aug 30, 2026 at 2:17 PM UTC · 2 分钟阅读

Market Impact
SOL+1.23%$106.14
Last Updated
3 小时前
Researchers say all 16 malicious modules uncovered in the campaign serve distinct purposes and are designed to be "highly extensible."
The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024.
Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware.
According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically.
One example is the "Enable Right Click & Copy — Smart Unlock + OCR" extension, the only one in the campaign available for both Chrome and Edge, which had a Chrome user base of at least 70,000 when it turned malicious. The number of installs on Edge was 10,000 at the time.
Google caught the threat early and removed the extension from its add-ons marketplace, but at the time of Socket publishing its report, the Edge version remained available.
Market Context
Article Intelligence
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
