Overview
- Researchers at Socket uncovered 19 Chrome and Edge extensions that were injected with malware and have been delisted from the official stores but remain installed on users' browsers.
- The attackers used a retrofit pattern by releasing benign extensions or buying five existing add-ons, then pushing malicious updates that installed backdoors and linked infected browsers to command‑and‑control servers.
- The malware harvested passwords, browser history and social data from Facebook and LinkedIn and could exfiltrate crypto tokens and drain wallets on Solana, Tron and EVM‑compatible chains.
- A single extension, Enable Right Click & Copy — Smart Unlock + OCR, had about 70,000 Chrome installs and 10,000 Edge installs, leaving tens of thousands of users exposed unless they manually remove the add‑ons.
- Socket published the full list of infected extensions and remediation advice so users can uninstall the add‑ons, rotate credentials, and check and secure affected crypto wallets while platforms investigate the actors' infrastructure.