Follow the latest coverage, related explainers and connected technology stories.
Socket uncovered a campaign that used 19 extensions for Google Chrome and Microsoft Edge to distribute a malicious software framework capable of stealing cryptocurrency, account data, and browsing history, while injecting fraudulent ClickFix pages. The investigation’s findings indicate that the activity may have started as early as the beginning of 2024, and that some extensions became malicious tools after attackers acquired them and automatically updated them.