19 Chrome and Edge Extensions Found Carrying Password & Crypto-Stealing Malware

Researchers at Socket have uncovered 19 malicious browser extensions capable of stealing login information, targeting cryptocurrency wallets and delivering additional malicious code.

The investigation identified 18 Chrome extensions and one Microsoft Edge extension linked through similar code and attack techniques. Researchers connected the activity to a wider campaign that appears to have been operating since 2024.

What makes the campaign unusual is how some of the malicious extensions reached users.

Legitimate extensions were bought and weaponized

According to Socket, 14 of the extensions were created by the attackers, while five began as legitimate extensions that were later acquired and updated with malicious functionality.

This approach can make an attack particularly difficult for users to spot. Someone may install a safe extension and use it for months before a later automatic update introduces malicious code.

The largest potential exposure involved “Enable Right Click & Copy — Smart Unlock + OCR.” The Chrome version had around 70,000 users when malicious functionality was introduced, while a related Edge version had around 10,000 users. Socket cautioned that these figures do not necessarily mean every user received the infected version.

Malware targets wallets, passwords and accounts

The extensions use a flexible malware system capable of downloading different attack modules from remote servers.

Researchers observed tools designed to hijack cryptocurrency wallet transactions, steal wallet recovery phrases, collect login information and capture authenticated sessions from cryptocurrency exchanges. Other modules could record information entered into forms, steal browsing history and target Facebook or LinkedIn accounts.

One technique also displayed fake browser update warnings that attempted to persuade users to run attacker-supplied commands on their computers.

Browser extensions can change after installation

Socket said the broader campaign demonstrates an important risk with browser extensions: software that was trustworthy when installed may not remain that way if ownership changes or a later update introduces malicious behavior.

The researchers recommend regularly reviewing installed extensions and removing those that are no longer needed or appear suspicious.

Users should also be cautious with extensions that request broad access to websites, browsing data or other sensitive information, particularly when that access is unnecessary for the extension’s main purpose.