Researchers at Socket uncovered a campaign involving at least 16 malicious modules distributed through browser extensions on the Chrome Web Store and Microsoft Edge Add-ons. The extensions initially appeared legitimate, providing advertised functionality without containing malware. However, some were acquired from original creators and later injected with malicious code through automatic updates.
One highlighted extension, “Enable Right Click & Copy — Smart Unlock + OCR,” had a Chrome user base of at least 70,000 when it turned malicious, with 10,000 installs on Edge. Google removed the extension from the Chrome Web Store, but at the time of Socket’s report, the Edge version remained available.
Once installed, the malware establishes an encrypted WebSocket connection to command-and-control servers. It downloads JavaScript modules, removes Content Security Policy headers from visited websites, and injects malicious scripts through hidden HTML elements. The modules can drain EVM, Solana, and Tron wallets by hijacking legitimate “Connect Wallet” and “Swap” buttons. They also replace Ledger and Trezor websites with convincing seed-phrase phishing pages, steal sessions and balances from major exchanges and wallets including Coinbase, Binance, Kraken, and MetaMask, and harvest credentials, form entries, Facebook and LinkedIn account information, and browser history. Additionally, the malware displays ClickFix-style fake browser updates that trick users into executing attacker-provided commands.
Socket warns that the malicious framework may have more modules, and as the malware evolves, new payloads are expected to be deployed. At the time of publishing, none of the malicious extensions remain on the Chrome Web Store.