Published on August 30, 2026

Chrome Web Store extensions caught stealing crypto, browser data


Severity

Medium

Detail

Security researchers have identified 19 malicious extensions for Google Chrome and Microsoft Edge that deliver an extensible malware framework capable of stealing cryptocurrency, browser data, credentials, and session information.

The campaign was uncovered by application security company Socket and may have been active since early 2024. The malicious extensions contain different modules that allow attackers to perform cryptocurrency theft, credential harvesting, browser data collection, and ClickFix-style social engineering.

How?

Several of the extensions were initially published as legitimate tools that provided their advertised functionality without malicious code. According to researchers, five extensions were later acquired from their original developers and modified through subsequent updates to introduce the malware.

One of the affected extensions, “Enable Right Click & Copy — Smart Unlock + OCR,” had at least 70,000 Chrome users and 10,000 Edge users when the malicious activity was identified. Google subsequently removed the Chrome version from the Chrome Web Store, while the Edge version remained available when Socket published its findings.

Once installed, the extensions establish encrypted WebSocket connections with command-and-control (C2) infrastructure and can retrieve additional JavaScript modules based on the attacker’s requirements.

The malware also modifies browser security controls by removing Content Security Policy (CSP) headers from visited websites. It can then inject malicious scripts through hidden HTML elements, allowing additional modules to operate within websites accessed by the victim.

The malware framework includes multiple capabilities targeting cryptocurrency users and online accounts. These include hijacking legitimate “Connect Wallet” and “Swap” functions to drain EVM, Solana, and Tron wallets, as well as replacing legitimate Ledger and Trezor websites with fake pages designed to capture cryptocurrency seed phrases.

Other modules can steal session information, authentication tokens, account details, and cryptocurrency balances from services including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask.

The extensions can also capture credentials and form data entered across websites, collect information from Facebook and LinkedIn accounts, and exfiltrate browser history.

In addition to credential and cryptocurrency theft, the malware can display ClickFix-style fake browser update prompts that instruct victims to execute attacker-provided commands, providing another method for delivering malicious activity to compromised systems.

Researchers noted that the malware framework is highly extensible, allowing additional modules and capabilities to be deployed over time. This means the current capabilities may not represent the full scope of the campaign, and new malicious payloads could be introduced through future updates.

At the time of publication, none of the identified malicious extensions remained available on the Chrome Web Store. Socket’s investigation also identified the extension IDs associated with the campaign and the domains used for C2 communication.

Extension IDExtension Name
pkoccklolohdacbfooifnpebakpbeipcEnable Right Click & Copy — Smart Unlock + OCR
fegckejpfnlmfgkfjpinlbgmeeijjkelRapidLens – Google Lens for Screen Search & Images
kdenlnncndfnhkognokgfpabgkgehoddQuickLens – Search Screen with Google Lens
jamminefolhgepgihbmcjjhgldbfcikpPassword Protect PDF
inmkjedjdhgpknjogbjomhnbgdccckkgAllow Copy – Select & Enable Right Click (Edge extension)
fcgdejjichpgfaaafflplhfijcnieopbPixelCheck
cfpnjdbpojpcongfaefcamjbaolpelcdCreative Library – Ad Spy Tool
aapdalkmclfaahehnmicbglkohkldhneWebsite Traffic Checker: MirrorSphere SEO Stats
dkdadldmiefjldmegbjbnhhfddnkhlhmSite Signal – Website Traffic & SEO Checker
fjmlhlkccegopebcllcmafahkmeejpphSEO Pulse Pro – Website Traffic & SEO Analyzer
iekoapohahgmogbagegmcgplbkikcgkePrivate Crypto News Reader
ahpnnnjbnfbhoikhohglpohnoocjcoco Blockfolio: Address Monitor
oeacadlaclegkkkdehjmiifnjhcekcljCrypto Rates & Fiat Converter
jmlgannjlbliikgcaieomgmcnfplgleaCrypto Alerter: Price Alarms & Volatility Warnings
lhmcajhgadanidbopgaoobjlldegjmkeDeFi Pulse Tracker
gfackggoapepdmnjnkblogdcjpgcjiakCrypto Price Badge: Quick Glance
hfijkbdkpidafdbeebnnkhfccildbcleMulti-Chain Explorer
pcngchfbfgejllcbhmeadjhiebebiomeLedgerLook: Wallet Checker
aodkjdeghbjiaienipfjkbpcikkacbcpMeta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray

Users who previously installed any of the identified extensions should treat the device and associated accounts as potentially compromised. Login credentials should be changed, particularly for accounts accessed while the malicious extension was installed.

Cryptocurrency users potentially affected by the campaign should consider moving their assets to a newly created wallet and reviewing their existing wallets for unauthorized activity.

Source

https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/