Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: chrome-extensions (4 articles)Clear

Trusted browser extensions turned into crypto stealers through ownership handoffs

Researchers at Socket detailed a long-running campaign, active since early 2024, in which Chrome and Edge extensions delivered an extensible malware framework of sixteen modules to steal cryptocurrency, credentials, session tokens, and browsing data, and to inject ClickFix lures. Notably, several extensions started out legitimate and were only weaponized later, after their original developers handed over control and new owners pushed malicious automatic updates. One extension reached seventy thousand users before removal. The malware ran from the extension's background worker, opened an encrypted connection to its servers, and displayed fake wallet-recovery pages on real crypto sites to capture recovery phrases.

Check
Audit installed Chrome and Edge extensions, remove unneeded ones, and recognize that a once-safe extension can turn malicious through an update after its ownership changes, silently and without a new prompt.
Affected
Users of the affected Chrome and Edge extensions, especially crypto holders; the framework steals wallet recovery phrases, credentials, session cookies, and browsing data, and can prompt users into running attacker commands.
Fix
Restrict extension installs through browser policy, review extension permissions, keep crypto wallets off browsers used for general work, monitor for the campaign's indicators, and move funds if a compromised extension was installed.

Cluster of 19 Chrome and Edge extensions steal wallets and drain crypto

Researchers at Socket found a coordinated cluster of nineteen browser extensions, eighteen for Chrome and one for Edge, published over the past six months with code to steal cryptocurrency wallet secrets, drain funds, harvest credentials, and inject code into targeted websites. The extensions share code and tradecraft, suggesting a single campaign that may have run even longer. Because a browser extension can read and alter the pages a user visits, a malicious one that reaches a crypto user can quietly capture recovery phrases or redirect transactions. This continues a steady pattern of wallet-draining extensions slipping into official browser stores under the guise of useful tools.

Check
Review the browser extensions installed across your users, remove unknown or wallet-related ones from this cluster, and remind crypto users that a single malicious extension can drain their funds.
Affected
Users who installed any of the nineteen malicious Chrome or Edge extensions, especially cryptocurrency holders; the extensions steal wallet secrets, drain funds, harvest credentials, and can tamper with the websites users visit.
Fix
Restrict extension installation through browser policy, allowlist trusted publishers, audit installed extensions periodically, keep crypto wallets off browsers used for general browsing, and treat any exposed wallet as compromised.

Socket finds 737 free VPN Chrome extensions routing user traffic through proxies

Researchers at Socket identified a campaign of 737 free virtual private network and proxy extensions published across browser marketplaces that route users' web traffic through outside proxy servers. Many impersonate well-known brands to appear trustworthy, so a user installing what looks like a legitimate free VPN can instead have their browsing redirected through infrastructure they do not control. Because a browser extension can see and alter the pages a user visits, routing traffic this way exposes browsing activity and can enable interception. Free VPN and proxy extensions are a recurring source of this problem, trading the promise of privacy for the opposite.

Check
Review the browser extensions installed across your users for free VPN or proxy tools, remove untrusted ones, and prefer reputable, audited services over free extensions that route traffic through unknown servers.
Affected
Users who installed free VPN or proxy browser extensions, including brand-impersonating ones; their web traffic can be routed through servers the operator controls, exposing browsing activity and enabling interception.
Fix
Restrict which browser extensions users can install through policy, allowlist trusted publishers, audit installed extensions periodically, and educate users that free VPN extensions often monetize by handling their traffic.

Malicious JetBrains plugins steal developers' AI API keys on entry

Aikido Security uncovered a coordinated campaign of at least 15 malicious plugins on the JetBrains Marketplace that pose as AI coding assistants but secretly steal the AI provider API keys developers enter. The plugins offer real features like chat, code review, and commit messages, so they work as advertised, but the moment a user pastes in an OpenAI, DeepSeek, or SiliconFlow key and clicks Apply, the key is silently sent to an attacker server over plain HTTP, with no prompt. The campaign has run since late October 2025, with new plugins as recent as June 10, and uses inflated downloads and fake reviews. Separately, malicious Chrome extensions were found capturing chatbot conversations.

Check
Review which JetBrains IDE plugins and browser extensions developers have installed, especially AI-assistant tools, and check whether any AI provider API keys were entered into third-party plugins rather than official integrations.
Affected
Developers who installed the malicious JetBrains AI-assistant plugins and entered OpenAI, DeepSeek, or SiliconFlow API keys; users of malicious Chrome extensions that harvest chatbot conversations are also exposed.
Fix
Remove untrusted AI plugins and extensions, rotate any AI provider API keys that were entered into them, restrict key permissions and spend limits, and source AI tooling only from vetted, official publishers.