Socket Identified 19 Malicious Chrome and Edge Extensions

Socket’s analysis describes 19 malicious extensions containing modular malware that could steal login credentials, sessions, and crypto wallet data.

Researchers at Socket identified malicious extensions for Chrome and Microsoft Edge. There are 19 add-ons in total—18 for Chrome and one for Edge—which, according to their technical analysis, shared a mechanism for communicating with attackers’ servers and downloading additional malicious modules.

This is not merely a theoretical vulnerability issue. Socket describes a campaign in which the affected extension versions could steal passwords, form contents, browsing data, active sessions, and crypto wallet-related data. One of the identified extensions has already been removed from the Chrome Web Store, while the status of the related version in the Microsoft Edge Add-ons catalog had not been independently confirmed as of August 30.

Malicious extensions used modules downloaded at runtime

According to Socket, the extensions first interfered with the security policies of visited websites. They removed Content Security Policy headers, which help limit the loading and execution of untrusted content. They could then inject their own scripts into pages.

Additional functions were not supposed to be located directly in the add-on’s core code. According to the analysis, the extensions downloaded them via WebSocket from servers controlled by attackers. This modular approach allows malware capabilities to be changed or expanded without requiring a new update made available in the extension store.

Socket documented 16 modules. Their functions included stealing data from forms and browsing history, abusing crypto exchange sessions, and phishing for recovery phrases from hardware crypto wallets. The mechanisms also included ClickFix-style lures that may prompt users to execute a command in the operating system.

Five add-ons reportedly changed owners before the malicious update

Researchers said that five of the captured extensions had been purchased from their original authors, with the malicious code added only in a subsequent update. They concluded that the campaign actor created the remaining extensions.

This approach illustrates the risk posed by add-ons that may initially appear trustworthy or already have an established user base. An extension’s automatic update can deliver new code without the user reinstalling the add-on. At the same time, attackers did not necessarily need to include all malicious functionality directly in the version that passed publication in the store.

Socket identified “Enable Right Click & Copy — Smart Unlock + OCR” as the add-on removed from the Chrome Web Store. As of August 27, its related Edge version was reportedly still active; the company reported it to Microsoft. Independent confirmation of the item’s current status as of August 30 was not available.

The number of affected users is unknown

It has not been confirmed how many people installed the malicious versions or whether, and to what extent, accounts, data, or cryptocurrency were stolen. Socket estimated potential exposure at approximately 80,000 users based on the user counts of two extensions. However, this figure does not represent the number of victims.

Likewise, Socket’s attribution of all 19 add-ons to a single actor and the possible connection to older activity dating back to February 2024 are analytical conclusions, not publicly confirmed findings by law enforcement authorities.

What users should do

Users who have any of the identified extensions installed should remove them. Given the malware’s recorded capabilities, it is advisable to change passwords and invalidate active sessions for affected services from a trusted device.

If a crypto wallet is suspected of being compromised, users should follow the security guidance provided by its provider. Further developments will also depend on whether Microsoft confirms the removal of the Edge version and whether independently verified cases of abuse or new indicators of compromise emerge.

Sources

  • Socket – The primary technical analysis states the number of extensions, their identifiers, how they operate, the documented modules, their removal status from the Chrome Web Store, and the status of the Edge version at the time of publication.
  • BleepingComputer – Independent coverage from August 30, 2026, summarizes Socket’s findings, including the malware’s functions and removal from the Chrome Web Store.

Verified and updated: 08/30/2026 16:59

Sharing