Illustrative image generated with AI
Chrome and Edge Extensions Turned into Malware: 19 Modules to Steal Crypto, Seed Phrases, and Sessions
Discover how 19 malicious modules in Chrome and Edge extensions steal crypto, seed phrases, and sessions. Learn immediate steps to secure your accounts.
Text generated by artificial intelligence, published without human review. AI transparency
On 30 August 2026, Socket, an application security company, published details of a campaign that abused Google Chrome and Microsoft Edge extensions to distribute a malicious JavaScript framework. The framework is described as highly extensible: researchers identified 19 modules with different functions and warn that new payloads may be added over time. The activity may have started in early 2024.
A Modular Framework Injected via Extension Updates
Socket observed that many extensions, when first published, delivered the promised functionality and contained no malicious code. Five of them were acquired from the original creators and later infected through automatic updates. This method allowed apparently legitimate tools to be turned into malware without users having to install anything new.
From a technical perspective, after installation the malicious code establishes an encrypted WebSocket connection to command-and-control servers. From there it downloads additional JavaScript modules. On every site visited, it removes Content Security Policy headers and injects scripts via hidden HTML elements. In practice, the protection browsers use to limit the execution of unauthorized code is disabled.
The 19 modules observed cover different functions: some drain wallets, others steal credentials, and still others record what the user types into forms.
The 19 Extensions Involved and the 80,000-User Case
The most striking case concerns "Enable Right Click & Copy — Smart Unlock + OCR". When it became malicious it had at least 70,000 users on Chrome and 10,000 on Edge. Google removed it from the Chrome Web Store; at the time Socket published its report, the Edge version was still available in the Microsoft Edge Add-ons.
At the time of publication, none of the malicious extensions were present in the Chrome Web Store, while some were still downloadable from the Edge store. Socket published the complete list of IDs, useful for checking a suspicious installation.
| Extension ID | Extension Name |
|---|---|
| pkoccklolohdacbfooifnpebakpbeipc | Enable Right Click & Copy — Smart Unlock + OCR |
| fegckejpfnlmfgkfjpinlbgmeeijjkel | RapidLens - Google Lens for Screen Search & Images |
| kdenlnncndfnhkognokgfpabgkgehodd | QuickLens - Search Screen with Google Lens |
| jamminefolhgepgihbmcjjhgldbfcikp | Password Protect PDF |
| inmkjedjdhgpknjogbjomhnbgdccckkg | Allow Copy - Select & Enable Right Click (Edge extension) |
| fcgdejjichpgfaaafflplhfijcnieopb | PixelCheck |
| cfpnjdbpojpcongfaefcamjbaolpelcd | Creative Library - Ad Spy Tool |
| aapdalkmclfaahehnmicbglkohkldhne | Website Traffic Checker: MirrorSphere SEO Stats |
| dkdadldmiefjldmegbjbnhhfddnkhlhm | Site Signal - Website Traffic & SEO Checker |
| fjmlhlkccegopebcllcmafahkmeejpph | SEO Pulse Pro - Website Traffic & SEO Analyzer |
| iekoapohahgmogbagegmcgplbkikcgke | Private Crypto News Reader |
| ahpnnnjbnfbhoikhohglpohnoocjcoco | Blockfolio: Address Monitor |
| oeacadlaclegkkkdehjmiifnjhcekclj | Crypto Rates & Fiat Converter |
| jmlgannjlbliikgcaieomgmcnfplglea | Crypto Alerter: Price Alarms & Volatility Warnings |
| lhmcajhgadanidbopgaoobjlldegjmke | DeFi Pulse Tracker |
| gfackggoapepdmnjnkblogdcjpgcjiak | Crypto Price Badge: Quick Glance |
| hfijkbdkpidafdbeebnnkhfccildbcle | Multi-Chain Explorer |
| pcngchfbfgejllcbhmeadjhiebebiome | LedgerLook: Wallet Checker |
| aodkjdeghbjiaienipfjkbpcikkacbcp | Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray |
What the Malicious Modules Do: Wallets, Exchanges, and Fake Updates
The modules identified by Socket include direct attacks on cryptocurrencies. Some drain EVM, Solana, and Tron wallets by manipulating the legitimate "Connect Wallet" and "Swap" buttons present on DeFi sites. Another module replaces Ledger and Trezor pages with credible phishing versions to steal seed phrases, the recovery phrases that give full access to funds.
On the exchange front, the malware targets sessions, tokens, account data, and balances on Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. In parallel it records credentials and data entered into forms on all visited sites, collects information from Facebook and LinkedIn accounts, and exfiltrates browser history.
One module also displays fake browser updates in ClickFix style: the victim sees an alert that convinces them to run commands provided by the attackers, turning simple data theft into potential direct system access.
Consequences for Affected Users
Anyone who installed one of the listed extensions should consider their credentials compromised. The infection exposes passwords, sessions, tokens, form data, browsing history, account data, and wallet balances. Cryptocurrency holders face a concrete risk of losing funds, because the modules can sign transactions or steal recovery keys.
No specific versions were indicated: the verification criterion is the presence of the extension with the corresponding ID. The damage does not depend on the browser version, but on the installed extension.
What to Do Immediately: Removal, New Passwords, and Edge Check
Socket recommends some immediate actions. First, manually remove the suspicious extensions from Chrome and Edge. Then change passwords for all accounts at risk, prioritizing exchanges, wallets, social networks, and banking services. Anyone who owns cryptocurrency should transfer funds to a newly created wallet, not derived from the compromised one, as soon as possible.
For Edge users, a manual check is needed: at the date of the report some extensions were still available in the Microsoft Edge Add-ons, so automatic removal is not guaranteed. Socket's full report includes indicators of compromise, including the extension IDs and the domains used to communicate with command-and-control servers: these should be used to check network logs and block any residual connections.
If an extension has already been removed but the system has been exposed, changing credentials and moving funds remains the most urgent measure. The framework is designed to receive new modules: cleaning the browser does not eliminate the risk as long as credentials and wallets remain the same.
Sources
This article is an original reworking based on the sources below.
