Recently, cybersecurity researchers uncovered multiple Google Chrome and Microsoft Edge extensions that contained malicious code capable of stealing cryptocurrency and sensitive data. These extensions were published over the last six months and may have been active since February 2024. According to research from Socket, the malicious behavior of these extensions was implemented by initially releasing a legitimate version and later updating it with malicious code. The research indicates that 14 of the identified extensions were created by the threat actor, while the remaining five were purchased from their original developers. Notably, the "Enable Right Click & Copy - Smart Unlock + OCR" extension had a combined user base of 80,000 across Chrome and Edge browsers. Once installed, the malware establishes an encrypted connection with command-and-control servers, downloads JavaScript modules, and injects malicious scripts into websites visited by users. Researchers warn that these malicious extensions may continue to evolve, with new payloads expected in the future. Users are advised to change their passwords immediately and consider transferring their cryptocurrency assets to a new wallet.
Industry Insights · August 31, 2026
Security Issues with Chrome Extensions Raise Concerns
Recent findings reveal multiple Chrome and Edge extensions harboring malicious code for stealing cryptocurrency and sensitive data.

