Skip to content
Live newsroom 70 readers online
Thursday, September 3, 2026 Live Sync: Just now
BreakingPuerto Rican singer-songwriter Kany García brings her biggest tour yet to the US
Share Suggestions AVOID MSFT Stage 4 (Conv: 1/5 | Size: 10%)

Popular Chrome extensions were quietly weaponized to steal crypto from 80,000 users

Facepalm: Security experts recently uncovered a malicious campaign that had been active for years. Unknown cybercriminals abused Chrome's extension system to infect tens of thousands of systems, and many victims may still be vulnerable if they haven't manually changed their browser's configuration. Socket Inc. researchers have identified 19 malicious extensions targeting Chrome and Edge users. […]

By deepak · September 3, 2026 · 2 min read

Facepalm: Security experts recently uncovered a malicious campaign that had been active for years. Unknown cybercriminals abused Chrome's extension system to infect tens of thousands of systems, and many victims may still be vulnerable if they haven't manually changed their browser's configuration.

Socket Inc. researchers have identified 19 malicious extensions targeting Chrome and Edge users. The cybercriminal campaign primarily targeted Google's browser, but one extension gained significant popularity on both Chrome and Edge. In any case, the analysts believe a single "mind" is behind the campaign – and it's determined to keep going even after the extensions have been removed from both browsers' stores.

All of the malicious add-ons employed a similar strategy, Socket said. A majority of the extensions (14) were developed directly by the cybercriminals, while five others were purchased from legitimate developers and companies. Initially, the add-ons simply provided their advertised functionality. Over the past six months, however, the hackers updated the extensions with malicious code designed to compromise systems or start harvesting users' data.

The list of add-ons included a particularly popular extension named "Enable Right Click & Copy – Smart Unlock + OCR." It was ultimately installed on 70,000 Chrome browsers and another 10,000 Edge browsers. A total of 80,000 users were eventually exposed to the malicious extension, which primarily targeted crypto wallets and other cryptocurrency-related data.

The cybercriminals used some code-based attack patterns that were first identified in February 2024, Socket said. They injected malicious payloads after accumulating a considerable number of potential victims, managing the crypto-stealing campaign remotely through a flexible command-and-control domain infrastructure.

The malicious extensions were eventually removed from the Chrome and Edge stores. However, users might still be part of the C2 infrastructure if they haven't checked for and manually removed all 19 add-ons listed by researchers.

In 2018, Google announced a major change to the extension technology used by the Chromium project. The Manifest V3 API was intended to improve the security architecture of add-ons across Chromium-based browsers, including Chrome and Microsoft Edge.

As the 19 malicious extensions retrofitted with malicious payloads clearly show, Google's attempt to strengthen security might very well turn out to be wishful thinking. Cybercriminals are likely to continue targeting popular browser extensions even after Manifest V2 is gone.

Source: Read the original article on www.techspot.com

Important Legal & Financial Disclaimer

FutureKnowledge is an automated financial intelligence aggregator. The information provided on this website does not constitute investment advice, financial advice, trading advice, or any other sort of advice and you should not treat any of the website's content as such. We are not registered with the SEC, SEBI, or any regulatory agency. Automated AI-generated content may contain errors. Always conduct your own due diligence and consult your financial advisor before making any investment decisions.

© 2026 FutureKnowledge Intelligence. All rights reserved.