Malicious Chrome and Edge Extensions Target Cryptocurrency Wallets and Browser Data
Security researchers have uncovered a campaign involving multiple malicious Google Chrome and Microsoft Edge extensions that can steal cryptocurrency, sensitive account data, browser history, and credentials. The extensions can also inject fake ClickFix browser update prompts designed to trick users into executing attacker-provided commands.
Researchers identified 16 malware modules associated with the campaign. Each module appears to serve a specific purpose, allowing the attackers to scale the operation and deploy new capabilities as needed.
The campaign was discovered by application security company Socket, which said its investigation suggests the operation may have been active since early 2024.
Legitimate browser extensions compromised through updates
Socket reports that many of the extensions initially provided their advertised features and did not contain malicious code when they were first published in the Chrome Web Store.
However, researchers said five extensions were later acquired from their original developers and modified to include malware. The malicious code was then distributed through automatic extension updates, allowing the attackers to compromise existing users without requiring them to install a new extension.
One example is the “Enable Right Click & Copy — Smart Unlock + OCR” extension. It was the only extension identified in the campaign that was available for both Chrome and Edge. Before it was removed, the Chrome version had at least 70,000 users, while the Edge version had approximately 10,000 installations.
Google detected the threat and removed the Chrome extension from its marketplace. Socket said the Microsoft Edge version was still available when its report was published.

Source: Socket
How the malicious browser extensions operate
After installation, the malware establishes an encrypted WebSocket connection to a command-and-control (C2) server. It can then download JavaScript modules, remove Content Security Policy (CSP) headers from visited websites, and inject malicious scripts through hidden HTML elements.
According to Socket, the observed malware modules include capabilities for:
- Hijacking legitimate “Connect Wallet” and “Swap” buttons to drain EVM, Solana, and Tron cryptocurrency wallets
- Replacing Ledger and Trezor websites with convincing pages designed to steal wallet seed phrases
- Stealing sessions, authentication tokens, account information, and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask
- Recording credentials and form data entered on websites
- Collecting Facebook and LinkedIn account information
- Extracting browser history
- Displaying fake ClickFix-style browser update alerts that instruct victims to run commands supplied by the attackers

Source: Socket
Users urged to secure accounts and cryptocurrency wallets
Socket warned that the malicious framework may include additional modules. The researchers expect the attackers to deploy new payloads as the campaign develops.
At the time of publication, none of the identified malicious extensions were available in the Chrome Web Store.
The Socket report includes a complete list of extension IDs linked to the campaign, along with the domains used for command-and-control communications.
Anyone who has installed one of the affected extensions should assume that their credentials may have been exposed. Users should remove the extension, change their passwords from a trusted device, enable multifactor authentication, and review account activity for suspicious logins or transactions.
Cryptocurrency holders who may have interacted with an affected extension should move their assets to a newly created wallet as soon as possible. They should also avoid entering seed phrases or private keys into websites or browser pop-ups, even if the page appears to belong to a trusted hardware wallet provider.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




