Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2604+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Chrome Web Store Extensions Caught Stealing Crypto, Browser Data
Chrome Web Store Extensions Caught Stealing Crypto, Browser Data
NEWS

Chrome Web Store Extensions Caught Stealing Crypto, Browser Data

Socket found 19 modules across Chrome and Edge extensions running a malware framework that drains crypto wallets and steals browser data.

Dylan H.

News Desk

August 30, 2026
4 min read

What Happened

Security researchers at Socket uncovered 19 malicious modules distributed across multiple browser extensions on the Chrome Web Store and Microsoft Edge Add-ons store. The extensions deliver a modular malware framework that drains cryptocurrency wallets, steals browser data, and injects ClickFix-style fake browser-update lures. The campaign appears to have been active since early 2024, and one compromised extension alone — "Enable Right Click & Copy — Smart Unlock + OCR" — reached roughly 70,000 Chrome users and 10,000 Edge users.


Incident Details

AttributeValue
Discovered BySocket
Malicious Modules19
PlatformsChrome Web Store, Microsoft Edge Add-ons
Active SinceEarly 2024
Notable Extension"Enable Right Click & Copy — Smart Unlock + OCR" — ~70,000 Chrome + ~10,000 Edge installs
Targeted NetworksEVM chains, Solana, Tron
Targeted Exchanges/WalletsCoinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, MetaMask

How the Malware Framework Works

The framework establishes an encrypted WebSocket connection back to attacker-controlled command-and-control servers, then downloads additional JavaScript modules on demand. Once active, it strips Content Security Policy (CSP) headers from visited pages and injects malicious scripts through hidden HTML elements — allowing it to manipulate page content without triggering the browser protections that would normally block such injection.

Cryptocurrency Theft

  • Hijacking wallet interactions: The malware intercepts and hijacks legitimate "Connect Wallet" and "Swap" buttons on sites interacting with EVM-compatible chains, Solana, and Tron.
  • Fake hardware-wallet pages: It replaces legitimate Ledger and Trezor sites with phishing pages designed to harvest seed phrases.
  • Exchange session theft: It steals sessions and account data from major exchanges including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, and Bybit, as well as from MetaMask.

Beyond Crypto

The framework also harvests general browser history and credentials across visited sites, along with Facebook and LinkedIn account data. It further deploys ClickFix-style fake browser-update prompts that trick victims into manually executing attacker-supplied commands — a technique increasingly common across unrelated malware families this year.


Impact Assessment

Impact AreaDescription
Financial TheftDirect drainage of connected crypto wallets via hijacked wallet-interaction buttons
Credential ExposureHarvested browser history, saved credentials, and social-media account data
Exchange Account RiskStolen sessions from major exchanges could allow unauthorized trading or withdrawals
ScaleAt least one extension in the campaign reached ~80,000 combined Chrome and Edge installs
Detection EvasionCSP-stripping and hidden-element injection let the malware operate without obvious visual tampering

Recommendations

For Affected Users

  • Remove any suspicious or unfamiliar extensions immediately, especially ones with broad host permissions.
  • Change passwords for all accounts accessed from the affected browser, and assume credential compromise.
  • Move cryptocurrency to a newly created wallet if you interacted with any wallet-connect prompts while a malicious extension was installed.
  • Review connected-app permissions on exchange accounts (Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit) and revoke anything unrecognized.
  • Enable hardware-wallet transaction verification, and never enter a seed phrase into a website — legitimate wallet software never asks for it that way.

For Organizations

  • Restrict browser-extension installation to an approved allowlist via enterprise policy.
  • Periodically audit installed extensions for permission scope creep following updates, since this campaign relied on malicious updates to previously legitimate extensions.
  • Monitor outbound WebSocket connections from managed endpoints for unexpected destinations.

Key Takeaways

  1. Socket identified 19 malicious modules across Chrome and Edge extensions running a shared malware framework.
  2. The framework strips CSP protections and injects hidden scripts to hijack wallet-connect flows across EVM, Solana, and Tron.
  3. Fake Ledger/Trezor pages and stolen exchange sessions extend the theft beyond browser-based wallets to major exchanges.
  4. The campaign also harvests general browser credentials and deploys ClickFix-style fake update lures.
  5. One compromised extension alone reached roughly 80,000 combined installs, and the campaign has reportedly run since early 2024.

Sources

  • BleepingComputer — Chrome Web Store extensions caught stealing crypto, browser data
#Malware#Browser Extensions#Cryptocurrency#Google Chrome#Microsoft Edge

Related Articles

737 Chrome VPN Extensions Caught Routing Traffic Through Attacker Proxies

Socket researchers found 737 fake Chrome VPN extensions silently routing 75,000+ users through SOCKS5 proxies on port 1082, enabling full AiTM interception.

4 min read

Google and Microsoft Pull ModHeader After Hidden Tracker Found in 1.6M-Install Extension

Google and Microsoft have removed ModHeader — a popular HTTP header editor with 1.6 million installs across Chrome and Edge — after researchers discovered...

4 min read

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

Security researchers at Island discovered that 'Adblock for YouTube,' a Chrome extension with over 10 million installs and a Featured badge, contains a...

3 min read
Back to all News