Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures.
Researchers say all 19 malicious modules uncovered in the campaign serve distinct purposes and are designed to be “highly extensible.”
The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024.
Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware.
According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically.
Advertisement
One example is the “Enable Right Click & Copy — Smart Unlock + OCR” extension, which had a Chrome user base of at least 70,000 when it turned malicious. The number of installs on Edge was 10,000 at the time.
Google caught the threat early and removed the extension from its add-ons marketplace, but at the time of Socket publishing its report, the Edge version remained available.
Malicious extensions available on the Edge add-ons store Source: Socket
Once installed, the malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from every website visited, and injects malicious scripts into websites through hidden HTML elements.
Socket observed malware modules with the following capabilities:
Draining EVM, Solana, and Tron wallets by hijacking legitimate “Connect Wallet” and “Swap” buttons
Replacing Ledger and Trezor websites with convincing seed-phrase phishing pages
Stealing sessions, tokens, account data, and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask
Recording credentials and form entries across websites
Harvesting Facebook and LinkedIn account information
Exfiltrating browser history
Displaying ClickFix-style fake browser updates that instruct victims to execute attacker-provided commands
Crypto wallet seed theft page Source: Socket
Socket warns that the malicious framework may have more modules and that as the malware evolves over time, new payloads are expected to be deployed.
At the time of publishing, none of the malicious extensions are available in the Chrome Web Store.
Advertisement
Socket’s report provides the full list of extension IDs uncovered in the campaign along with the domains used for C2 communication.
Extension ID
Extension Name
pkoccklolohdacbfooifnpebakpbeipc
Enable Right Click & Copy — Smart Unlock + OCR
fegckejpfnlmfgkfjpinlbgmeeijjkel
Advertisement
RapidLens – Google Lens for Screen Search & Images
kdenlnncndfnhkognokgfpabgkgehodd
QuickLens – Search Screen with Google Lens
jamminefolhgepgihbmcjjhgldbfcikp
Password Protect PDF
inmkjedjdhgpknjogbjomhnbgdccckkg
Allow Copy – Select & Enable Right Click (Edge extension)
You must be logged in to post a comment Login