A coordinated cybercriminal campaign has compromised at least 19 browser extensions on the Chrome Web Store and Microsoft Edge Add-ons store, impacting tens of thousands of users. According to new research from Socket Inc., the threat actors behind the operation have demonstrated a high level of persistence and adaptability, likely continuing their efforts even after the malicious add-ons were removed from official distribution platforms.
The investigation revealed that the primary target was Google’s Chrome browser, though a significant number of Microsoft Edge users were also exposed. Analysts at Socket believe a single entity or “mind” is orchestrating the campaign, which has evolved significantly over the past six months.
The malicious extensions utilized a similar operational pattern. While 14 of the extensions were originally developed by the cybercriminals themselves, five others were acquired from legitimate developers and companies. This acquisition pattern provided the hackers with an existing user base that had already trusted the software. Initially, these extensions functioned exactly as advertised, providing their standard utility to maintain a facade of legitimacy. However, in recent months, the operators pushed updates that injected malicious code designed to compromise systems and harvest sensitive user data.
Among the compromised add-ons, one stood out due to its significant user base. The extension named “Enable Right Click & Copy – Smart Unlock + OCR” was installed on 70,000 Chrome browsers and an additional 10,000 Edge browsers, exposing a total of 80,000 users. The malicious version of this specific tool primarily targeted cryptocurrency wallets and related digital asset data.
Technical analysis traced the code patterns back to February 2024, when they first appeared. The attackers took a patient approach, waiting until they had built up a large number of victims before deploying the malicious payloads. They managed the data-harvesting operation remotely, using a flexible command-and-control domain setup.

While the extensions have since been removed from the Chrome and Edge stores, the threat may persist for users who have not manually uninstalled the software. If the extensions are still present in a browser, they may still be able to communicate with the attackers’ infrastructure.
In 2018, Google announced the Manifest V3 API, a major change to the extension technology used by the Chromium project. The shift was designed specifically to improve the security architecture of add-ons across Chromium-based browsers, including Chrome and Microsoft Edge.
However, the fact that 19 extensions were retrofitted with malicious payloads suggests these security improvements may not be fully achieving their goal. Researchers expect cybercriminals to keep targeting popular browser extensions as an attack vector, even as older systems like Manifest V2 are phased out.
Users are urged to review their installed extensions and ensure none of the add-ons identified by Socket Inc. remain active in their browsers.
Maybe you would like other interesting articles?

