A sophisticated malware operation has been uncovered targeting users of Google Chrome and Microsoft Edge, with numerous browser extensions found to be distributing a potent malware framework. This framework is designed to exfiltrate cryptocurrency, sensitive personal data, and browser history, while also employing deceptive tactics such as injecting "ClickFix" lures. The alarming discovery, made by application security firm Socket, suggests this campaign may have been actively exploiting users since early 2024, compromising the trust users place in browser add-ons.
The Scope and Modus Operandi of the Attack
Researchers at Socket identified a total of 19 distinct malicious modules within this framework, each engineered with specific functionalities and possessing a high degree of extensibility. This modular design allows attackers to adapt and deploy new payloads as needed, making the threat dynamic and difficult to fully contain. Initially, many of these extensions presented themselves as legitimate tools, offering the advertised functionalities when first published on the Chrome Web Store and Microsoft Edge Add-ons store. However, the true malicious intent was revealed through a calculated takeover strategy.
A particularly concerning tactic involved attackers acquiring legitimate, popular extensions from their original developers and then injecting them with malware via automatic updates. This stealthy approach meant that unsuspecting users, who had already integrated these extensions into their daily browsing habits, were unknowingly subjected to malicious activity.
One prominent example highlighted by Socket was the "Enable Right Click & Copy – Smart Unlock + OCR" extension. At the time it turned malicious, this extension boasted a significant user base, with at least 70,000 installations on Chrome and an additional 10,000 on Edge. Such widespread adoption amplified the potential impact of the attack. While Google acted swiftly to remove this specific extension from its Web Store, at the time Socket’s report was published, the malicious version remained accessible on the Microsoft Edge Add-ons store, underscoring the ongoing challenges in safeguarding browser marketplaces.

Technical Details of the Malware Framework
Once installed, the malicious extensions establish a covert communication channel with command-and-control (C2) servers through encrypted WebSockets. This encrypted connection allows for the secure exfiltration of stolen data and the reception of further instructions or modules from the attackers. A critical component of the malware’s operation involves the manipulation of website security settings. It systematically removes Content Security Policy (CSP) headers from every website the user visits. CSP headers are crucial security mechanisms that help prevent cross-site scripting (XSS) and other code injection attacks. By stripping these headers, the malware creates vulnerabilities that allow it to inject malicious scripts into web pages.
These injected scripts are often hidden using concealed HTML elements, making them invisible to the user but capable of interacting with the web page’s content and functionality. This capability is central to the data theft operations.
The observed malware modules exhibit a range of alarming capabilities, including:
- Cryptocurrency Wallet Draining: The framework includes modules specifically designed to identify and interact with cryptocurrency wallet interfaces. These modules can steal sensitive wallet information, such as private keys or seed phrases, enabling attackers to transfer funds directly from the victim’s wallet. The visual evidence provided by Socket, depicting a "Crypto wallet seed theft page," starkly illustrates the direct threat to users’ digital assets.
- Sensitive Data Exfiltration: Beyond cryptocurrency, the malware is equipped to harvest a wide array of sensitive personal information. This can include login credentials, financial details, personal identification information, and any other data stored or entered by the user within their browser.
- Browser History and Cookie Theft: The malware can access and exfiltrate the user’s browsing history, providing attackers with insights into their online activities, interests, and potential targets for further social engineering. Cookies, which store session information and login tokens, can also be stolen, allowing attackers to hijack active user sessions.
- Click-Through Fraud (ClickFix Lures): The inclusion of "ClickFix" lures indicates a capability for deceptive advertising or phishing schemes. These lures likely trick users into clicking on malicious links or advertisements, generating fraudulent ad revenue for the attackers or leading users to further phishing sites.
- Information Stealing: Generic information-stealing modules are also present, capable of gathering a broad spectrum of data from the compromised system.
Timeline and Evolution of the Threat
While the exact genesis of the operation remains under investigation, Socket’s analysis suggests that the malicious framework has been active since at least early 2024. This indicates a prolonged period during which users could have been compromised without their knowledge. The modular nature of the malware suggests a continuous development cycle, with attackers likely refining their techniques and expanding their arsenal of modules. As the malware evolves, it is anticipated that new and more sophisticated payloads will be deployed, posing an ever-increasing threat to browser users.
The discovery process itself highlights the challenges in detecting such threats. Malicious actors often employ a "low and slow" approach, gradually introducing malicious code into seemingly benign extensions, waiting for them to gain traction before activating their full capabilities. The acquisition of popular extensions by threat actors is a particularly insidious tactic, leveraging the existing trust and user base to maximize the reach of their attacks.

Impact and Recommendations for Users
The implications of this campaign are severe. Users who have had any of the identified malicious extensions installed are strongly advised to assume that their credentials have been compromised. This necessitates immediate action:
- Password Changes: All login passwords for websites accessed through the compromised browser should be changed. This includes email accounts, social media, banking portals, and any other online services. It is crucial to use unique and strong passwords for each service, ideally managed through a reputable password manager.
- Multi-Factor Authentication (MFA): Users should enable multi-factor authentication wherever possible. MFA adds an extra layer of security, requiring more than just a password to access an account, significantly mitigating the risk of unauthorized access even if credentials are stolen.
- Cryptocurrency Security: For cryptocurrency holders, the threat is particularly acute. It is highly recommended to move any assets from potentially compromised wallets to a newly created, secure wallet. This new wallet should be generated using a trusted software or hardware wallet, and its recovery seed phrase should be stored offline and in a highly secure location.
The full list of malicious extension IDs and associated C2 domains, as provided by Socket, offers crucial information for users and security professionals to identify and remove these threats. The proactive identification and reporting of these extensions by Socket are vital steps in mitigating further damage.
Official Responses and Platform Security
Google’s swift action in removing the identified extensions from the Chrome Web Store demonstrates their commitment to user security. However, the continued presence of some malicious extensions on other platforms, such as Microsoft Edge, highlights the ongoing battle between platform security teams and malicious actors.
Microsoft, like Google, has security mechanisms in place to review and vet extensions submitted to their add-ons store. However, the dynamic nature of malware development means that sophisticated threats can sometimes evade initial detection. The fact that an extension remained available on the Edge store after being removed from Chrome suggests potential differences in detection methodologies or the speed of response between the two platforms.
H3: Ongoing Challenges in Browser Extension Security

The incident underscores a persistent vulnerability within the browser extension ecosystem. Extensions, by their nature, often require broad permissions to function effectively, granting them access to sensitive user data and browsing activities. This inherent access makes them attractive targets for malicious actors. The "supply chain" attack, where legitimate extensions are compromised and repurposed, is particularly effective because it bypasses the initial trust users have in the extension’s developer.
The extensible nature of browser platforms, while beneficial for user customization and productivity, also presents a challenge for security. The sheer volume of extensions available, coupled with the difficulty in continuously monitoring their behavior, creates an environment where malicious actors can operate with a degree of stealth.
Broader Implications and Future Outlook
This campaign serves as a stark reminder that the digital threat landscape is constantly evolving, with attackers becoming increasingly sophisticated in their methods. The reliance on browser extensions for various tasks, from productivity to security, makes them a critical vector for attack.
The modularity of the malware framework suggests a professional and organized criminal operation, likely with resources dedicated to ongoing development and deployment. The potential for these modules to be reused or adapted for other platforms or attack vectors cannot be discounted.
Security researchers and platform providers face an ongoing arms race. While detection tools and security policies are constantly being updated, attackers are also innovating. Users play a crucial role in this defense by remaining vigilant, practicing good cybersecurity hygiene, and critically evaluating the extensions they install.

The information provided by Socket, including the detailed list of compromised extensions, is invaluable for the security community and for end-users to protect themselves. As the digital world becomes increasingly interconnected, the security of seemingly minor components like browser extensions becomes paramount to safeguarding personal data and financial assets. The ongoing investigation into the full scope of this operation and the potential for further revelations remains a critical development in the fight against cybercrime.






