Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: edge-extensions (3 articles)Clear

Trusted browser extensions turned into crypto stealers through ownership handoffs

Researchers at Socket detailed a long-running campaign, active since early 2024, in which Chrome and Edge extensions delivered an extensible malware framework of sixteen modules to steal cryptocurrency, credentials, session tokens, and browsing data, and to inject ClickFix lures. Notably, several extensions started out legitimate and were only weaponized later, after their original developers handed over control and new owners pushed malicious automatic updates. One extension reached seventy thousand users before removal. The malware ran from the extension's background worker, opened an encrypted connection to its servers, and displayed fake wallet-recovery pages on real crypto sites to capture recovery phrases.

Check
Audit installed Chrome and Edge extensions, remove unneeded ones, and recognize that a once-safe extension can turn malicious through an update after its ownership changes, silently and without a new prompt.
Affected
Users of the affected Chrome and Edge extensions, especially crypto holders; the framework steals wallet recovery phrases, credentials, session cookies, and browsing data, and can prompt users into running attacker commands.
Fix
Restrict extension installs through browser policy, review extension permissions, keep crypto wallets off browsers used for general work, monitor for the campaign's indicators, and move funds if a compromised extension was installed.

Cluster of 19 Chrome and Edge extensions steal wallets and drain crypto

Researchers at Socket found a coordinated cluster of nineteen browser extensions, eighteen for Chrome and one for Edge, published over the past six months with code to steal cryptocurrency wallet secrets, drain funds, harvest credentials, and inject code into targeted websites. The extensions share code and tradecraft, suggesting a single campaign that may have run even longer. Because a browser extension can read and alter the pages a user visits, a malicious one that reaches a crypto user can quietly capture recovery phrases or redirect transactions. This continues a steady pattern of wallet-draining extensions slipping into official browser stores under the guise of useful tools.

Check
Review the browser extensions installed across your users, remove unknown or wallet-related ones from this cluster, and remind crypto users that a single malicious extension can drain their funds.
Affected
Users who installed any of the nineteen malicious Chrome or Edge extensions, especially cryptocurrency holders; the extensions steal wallet secrets, drain funds, harvest credentials, and can tamper with the websites users visit.
Fix
Restrict extension installation through browser policy, allowlist trusted publishers, audit installed extensions periodically, keep crypto wallets off browsers used for general browsing, and treat any exposed wallet as compromised.

Microsoft pulls 119 Edge extensions that hid malware inside images and fonts

Microsoft has removed 119 malicious Microsoft Edge extensions, tied to a single actor active since at least 2021, that hid their payloads inside ordinary image and font files using steganography. The extensions posed as ad blockers, VPNs, translators, and similar tools, worked as advertised, and stayed dormant for days while passing evasion checks, which let them survive in the store for years and reach up to 2.6 million installs. Beyond ad fraud and affiliate hijacking, the more dangerous variants stole Google credentials and two-factor codes at sign-in, harvested WordPress admin logins, and exfiltrated cookies for session hijacking, with extra aggression against corporate and banking targets. Microsoft has published indicators of compromise.

Check
Open your browser's extensions page and check installed add-ons against Microsoft's published list of StegoAd extension IDs, and review endpoints for the campaign's indicators of compromise across Chromium browsers.
Affected
Users who installed any of the 119 extensions, which posed as ad blockers, VPNs, and similar tools; stolen cookies and two-factor codes let attackers hijack sessions and accounts without passwords.
Fix
Remove any matching extension and treat the browser as compromised: reset Google and WordPress passwords, review sign-in activity, and prefer hardware security keys over SMS codes. Govern extensions with allowlists.