Malicious Chrome and Edge Extensions Caught Stealing Crypto, Browser Data

16-module malware framework deployed via compromised browser extensions, researchers say

edit
By LineZotpaper
Published
Read Time2 min
Multiple extensions for Google Chrome and Microsoft Edge have been found delivering a malware framework capable of stealing cryptocurrency, sensitive data, and browser history, according to application security firm Socket. The operation may have been active since early 2024.

Researchers at Socket uncovered a campaign involving at least 16 malicious modules distributed through browser extensions on the Chrome Web Store and Microsoft Edge Add-ons. The extensions initially appeared legitimate, providing advertised functionality without containing malware. However, some were acquired from original creators and later injected with malicious code through automatic updates.

One highlighted extension, “Enable Right Click & Copy — Smart Unlock + OCR,” had a Chrome user base of at least 70,000 when it turned malicious, with 10,000 installs on Edge. Google removed the extension from the Chrome Web Store, but at the time of Socket’s report, the Edge version remained available.

Once installed, the malware establishes an encrypted WebSocket connection to command-and-control servers. It downloads JavaScript modules, removes Content Security Policy headers from visited websites, and injects malicious scripts through hidden HTML elements. The modules can drain EVM, Solana, and Tron wallets by hijacking legitimate “Connect Wallet” and “Swap” buttons. They also replace Ledger and Trezor websites with convincing seed-phrase phishing pages, steal sessions and balances from major exchanges and wallets including Coinbase, Binance, Kraken, and MetaMask, and harvest credentials, form entries, Facebook and LinkedIn account information, and browser history. Additionally, the malware displays ClickFix-style fake browser updates that trick users into executing attacker-provided commands.

Socket warns that the malicious framework may have more modules, and as the malware evolves, new payloads are expected to be deployed. At the time of publishing, none of the malicious extensions remain on the Chrome Web Store.

§

Analysis

Why This Matters

  • Browser extensions have broad access to user data and can be weaponized after installation, making supply-chain attacks difficult to detect.
  • Cryptocurrency users are especially vulnerable: the malware targets wallet connections and exchange credentials, potentially draining accounts.
  • The campaign's longevity (since early 2024) and modular design suggest a sophisticated threat actor capable of adapting to browser store defenses.

Background

Browser extension attacks are a well-known vector for malware distribution. Attackers often purchase established extensions or compromise developer accounts to push malicious updates. Chrome and Edge both review extensions before listing, but updates can bypass manual review, a recurring problem in browser security. The ClickFix technique, which presents fake update prompts, has been used in other recent campaigns to trick users into running harmful commands.

Key Perspectives

Users: Rely on browser extensions for productivity but face risk from compromised or acquired extensions. The attack underscores the need to vet extensions carefully, monitor for unexpected behavior changes, and limit permissions. Google and Microsoft: As platform operators, they must balance developer freedom with security. Google removed the Chrome versions quickly, but the Edge version remained available at the time of reporting, raising questions about cross-store coordination and update monitoring. Security researchers (Socket): Highlight the extensible nature of the malware framework and predict new modules will appear. They emphasize that even well-reviewed extensions can turn malicious after an update.

What to Watch

  • Whether Microsoft removes the remaining Edge extension and issues a broader response.
  • If similar modules appear in other browser stores or using different initial lures.
  • Potential follow-up research uncovering additional compromised extensions or C2 infrastructure.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.