Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures.
Researchers say all 16 malicious modules uncovered in the campaign serve distinct purposes and are designed to be “highly extensible.”
The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024.
Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware.
According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically.
One example is the “Enable Right Click & Copy — Smart Unlock + OCR” extension, the only one in the campaign available for both Chrome and Edge, which had a Chrome user base of at least 70,000 when it turned malicious. The number of installs on Edge was 10,000 at the time.
Google caught the threat early and removed the extension from its add-ons marketplace, but at the time of Socket publishing its report, the Edge version remained available.

Source: Socket
Once installed, the malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from every website visited, and injects malicious scripts into websites through hidden HTML elements.
Socket observed malware modules with the following capabilities:
- Draining EVM, Solana, and Tron wallets by hijacking legitimate “Connect Wallet” and “Swap” buttons
- Replacing Ledger and Trezor websites with convincing seed-phrase phishing pages
- Stealing sessions, tokens, account data, and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask
- Recording credentials and form entries across websites
- Harvesting Facebook and LinkedIn account information
- Exfiltrating browser history
- Displaying ClickFix-style fake browser updates that instruct victims to execute attacker-provided commands

Source: Socket
Socket warns that the malicious framework may have more modules and that as the malware evolves over time, new payloads are expected to be deployed.
At the time of publishing, none of the malicious extensions are available in the Chrome Web Store.
Socket’s report provides the full list of extension IDs uncovered in the campaign along with the domains used for C2 communication.
Users who had any of the extensions installed should assume that their credentials have been compromised and change their login passwords.
Cryptocurrency holders potentially impacted by this campaign are recommended to move their assets to a newly created wallet as soon as possible.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.




