Cybersecurity

Malicious Chrome and Edge Extensions Stole Cryptocurrency and Browser Data

Socket uncovered a campaign that used 19 extensions for Google Chrome and Microsoft Edge to distribute a malicious software framework capable of stealing cryptocurrency, account data, and browsing history, while injecting fraudulent ClickFix pages. The investigation’s findings indicate that the activity may have started as early as the beginning of 2024, and that some extensions became malicious tools after attackers acquired them and automatically updated them.

2026-08-30
4 min read
8 views
فريق تحرير certi.news
Malicious Chrome and Edge Extensions Stole Cryptocurrency and Browser Data

Application security company Socket uncovered a malicious campaign that exploited extensions for Google Chrome and Microsoft Edge to distribute an extensible software framework that loads multiple JavaScript modules to steal cryptocurrency, sensitive data, and browsing history, in addition to injecting ClickFix-style fraudulent lures. The company says 19 malicious modules were identified in the campaign, each with a different function, while attackers may add new modules as the framework evolves.

The investigation’s findings indicate that the activity may have been operating since early 2024. Many of the extensions provided their advertised functionality when they were first published on the Chrome Web Store, before malware was injected through automatic updates after attackers acquired five extensions from their original developers.

How did the extensions work?

After the extension is installed, the malware establishes an encrypted WebSocket connection with command-and-control servers, then downloads JavaScript modules. It also removes Content Security Policy (CSP) headers from sites visited by the user and injects malicious scripts into web pages through hidden HTML elements.

Capabilities identified by Socket included draining EVM, Solana, and Tron wallets by hijacking “Connect Wallet” and “Swap” buttons, and replacing Ledger and Trezor websites with phishing pages requesting recovery phrases. Other modules were able to steal sessions, tokens, account data, and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask, in addition to recording login details and form fields, collecting information from Facebook and LinkedIn, and extracting browsing history.

The campaign also included ClickFix messages disguised as fake browser updates, attempting to persuade victims to execute commands specified by the attacker. This means the risk is not limited to stealing data stored in the browser, but extends to turning the user themselves into a channel for executing additional instructions.

Extensions identified by Socket

The published list includes the following extension names and IDs:

  • Enable Right Click & Copy — Smart Unlock + OCR — pkoccklolohdacbfooifnpebakpbeipc
  • RapidLens - Google Lens for Screen Search & Images — fegckejpfnlmfgkfjpinlbgmeeijjkel
  • QuickLens - Search Screen with Google Lens — kdenlnncndfnhkognokgfpabgkgehodd
  • Password Protect PDF — jamminefolhgepgihbmcjjhgldbfcikp
  • Allow Copy - Select & Enable Right Click — inmkjedjdhgpknjogbjomhnbgdccckkg
  • PixelCheck — fcgdejjichpgfaaafflplhfijcnieopb
  • Creative Library - Ad Spy Tool — cfpnjdbpojpcongfaefcamjbaolpelcd
  • Website Traffic Checker: MirrorSphere SEO Stats — aapdalkmclfaahehnmicbglkohkldhne
  • Site Signal - Website Traffic & SEO Checker — dkdadldmiefjldmegbjbnhhfddnkhlhm
  • SEO Pulse Pro - Website Traffic & SEO Analyzer — fjmlhlkccegopebcllcmafahkmeejpph
  • Private Crypto News Reader — iekoapohahgmogbagegmcplbkikcgke
  • Blockfolio: Address Monitor — ahpnnnjbnfbhoikhohglpohnoocjcoco
  • Crypto Rates & Fiat Converter — oeacadlaclegkkkdehjmiifnjhcekclj
  • Crypto Alerter: Price Alarms & Volatility Warnings — jmlgannjlbliikgcaieomgmcnfplglea
  • DeFi Pulse Tracker — lhmcajhgadanidbopgaoobjlldegjmke
  • Crypto Price Badge: Quick Glance — gfackggoapepdmnjnkblogdcjpgcjiak
  • Multi-Chain Explorer — hfijkbdkpidafdbeebnnkhfccildbcle
  • LedgerLook: Wallet Checker — pcngchfbfgejllcbhmeadjhiebebiome
  • Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray — aodkjdeghbjiaienipfjkbpcikkacbcp

What should users do?

Google removed the Enable Right Click & Copy — Smart Unlock + OCR extension from the Chrome Web Store after the threat was identified, but the Edge version was still available when Socket’s report was published. Socket said that none of the malicious extensions remained available on the Chrome Web Store at the time the report was published, although this does not eliminate the impact of previous installations.

Anyone who previously installed one of the extensions on the list should assume that their credentials may have been exposed and change the passwords used for affected accounts. Socket also recommends that affected cryptocurrency holders move their assets to a new wallet as soon as possible. The published list and command-and-control server identifiers provide a practical point of reference for verification, while the number of modules attackers may add later and the campaign’s full scope of impact remain open questions.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news