Researchers from application security firm Socket have uncovered a malware campaign distributed through browser extensions on the Chrome Web Store and Microsoft Edge Add-ons. The malicious framework deployed 16 distinct modules designed to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures into web pages. Socket’s investigation suggests the operation may have been active since early 2024, though many extensions initially offered legitimate functionality before turning malicious.
According to Socket, the extensions were often acquired from their original developers and then injected with malware through automatic updates. One example cited by the researchers is the “Enable Right Click & Copy - Smart Unlock + OCR” extension, the only one available for both Chrome and Edge. That extension had at least 70,000 users on Chrome and 10,000 on Edge when it became malicious, with Google removing the Chrome version from its store while the Edge version remained available at the time of the report’s publication.
Once installed, the malware established an encrypted WebSocket connection to command-and-control servers, allowing it to download JavaScript modules. It also stripped Content Security Policy headers from every website the user visited and injected malicious scripts into pages through hidden HTML elements. Socket warned that the framework may contain additional modules, and that new payloads are likely as the malware evolves.
Socket’s report includes the full list of extension IDs involved in the campaign along with the domains used for command-and-control communication. As of the report’s publication, none of the malicious extensions were available on the Chrome Web Store. Users who installed any of these extensions are advised to assume their login credentials have been compromised and change their passwords.
For cryptocurrency holders potentially affected, Socket recommends moving assets to a newly created wallet as soon as possible. The researchers emphasized that overall security scores can obscure what happens after initial access, noting that once attackers obtain valid credentials, prevention measures decline sharply. These findings are part of the broader context of the Blue Report 2026, which measures defenses technique by technique across 338 million simulations run in customer production environments.
The campaign highlights ongoing risks for US consumers who rely on browser extensions for everyday tasks, as malicious actors continue to exploit update mechanisms to push malware. While Google has removed the identified extensions from its store, users who previously installed them should take immediate steps to secure their accounts and digital assets. Socket’s investigation underscores the need for vigilance when installing or updating browser add-ons from any marketplace.
More software news from TechManNews.







