<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d" -->

---
title: Chrome Web Store extensions caught stealing crypto,...
description: Application security firm Socket uncovered a malware framework distributed through multiple Chrome and Edge extensions, some of which were legitimate before...
canonical: https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Chrome Web Store extensions caught stealing crypto, browser data | daily.dev
og:description: Application security firm Socket uncovered a malware framework distributed through multiple Chrome and Edge extensions, some of which were legitimate before...
og:url: https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d
og:image: https://api.daily.dev/og/posts/aooIbRY6d.png
og:image:alt: Chrome Web Store extensions caught stealing crypto, browser data
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Chrome Web Store extensions caught stealing crypto, browser data

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Application security firm Socket uncovered a malware framework distributed through multiple Chrome and Edge extensions, some of which were legitimate before being acquired and injected with malicious updates. The malware, potentially active since early 2024, uses 16 modules to drain EVM, Solana, and Tron crypto wallets, phish Ledger/Trezor seed phrases, steal credentials and sessions from exchanges like Coinbase and Binance, harvest Facebook/LinkedIn data, exfiltrate browser history, and display ClickFix-style fake update lures. One extension, 'Enable Right Click & Copy — Smart Unlock + OCR,' had 70,000 Chrome users and 10,000 Edge users before Google removed it; the Edge version reportedly remained available at time of publishing. Affected users are advised to change passwords and move crypto assets to new wallets.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data>

## Questions this post answers

### Can Chrome or Edge extensions turn malicious after they've already been installed and trusted?

Yes, several extensions in a campaign uncovered by Socket started out legitimate and malware-free, then were acquired from their original developers and injected with malicious code through automatic updates. One example, 'Enable Right Click & Copy — Smart Unlock + OCR,' had roughly 70,000 Chrome users and 10,000 Edge users when it turned malicious.

_daily.dev surfaces security research like this for developers auditing which browser extensions to trust._

### What should I do if I had a compromised crypto wallet browser extension installed?

Assume credentials have been compromised, change login passwords immediately, and move cryptocurrency holdings to a newly created wallet as soon as possible. The malicious modules were found draining EVM, Solana, and Tron wallets by hijacking 'Connect Wallet' and 'Swap' buttons, and phishing seed phrases via fake Ledger and Trezor pages.

_developers securing crypto-adjacent apps can track emerging wallet-drainer techniques on daily.dev._

### How does the ClickFix-style browser extension malware technique work?

It displays fake browser update prompts that instruct victims to manually execute attacker-provided commands, tricking users into running malicious code themselves. This was one of several modules deployed by a malware framework distributed through compromised Chrome and Edge extensions, alongside credential theft, session hijacking, and browser history exfiltration.

_daily.dev helps developers stay ahead of social-engineering tactics like ClickFix targeting end users._

---

Tags: [#devtools](https://daily.dev/tags/devtools), [#crypto](https://daily.dev/tags/crypto), [#malware](https://daily.dev/tags/malware), [#google-chrome](https://daily.dev/tags/google-chrome), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Chrome Web Store extensions caught stealing crypto, browser data","url":"https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d"},"datePublished":"2026-08-30T14:25:44.406Z","dateModified":"2026-08-30T14:26:40.525Z","description":"Application security firm Socket uncovered a malware framework distributed through multiple Chrome and Edge extensions, some of which were legitimate before...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d8dd23950a7f4f5cc1a1a52db238e66a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d8dd23950a7f4f5cc1a1a52db238e66a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"devtools,crypto,malware,google-chrome,phishing","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Chrome Web Store extensions caught stealing crypto, browser data"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/chrome-web-store-extensions-caught-stealing-crypto-browser-data-aooibry6d#faq","mainEntity":[{"@type":"Question","name":"Can Chrome or Edge extensions turn malicious after they've already been installed and trusted?","acceptedAnswer":{"@type":"Answer","text":"Yes, several extensions in a campaign uncovered by Socket started out legitimate and malware-free, then were acquired from their original developers and injected with malicious code through automatic updates. One example, 'Enable Right Click & Copy — Smart Unlock + OCR,' had roughly 70,000 Chrome users and 10,000 Edge users when it turned malicious. daily.dev surfaces security research like this for developers auditing which browser extensions to trust."}},{"@type":"Question","name":"What should I do if I had a compromised crypto wallet browser extension installed?","acceptedAnswer":{"@type":"Answer","text":"Assume credentials have been compromised, change login passwords immediately, and move cryptocurrency holdings to a newly created wallet as soon as possible. The malicious modules were found draining EVM, Solana, and Tron wallets by hijacking 'Connect Wallet' and 'Swap' buttons, and phishing seed phrases via fake Ledger and Trezor pages. developers securing crypto-adjacent apps can track emerging wallet-drainer techniques on daily.dev."}},{"@type":"Question","name":"How does the ClickFix-style browser extension malware technique work?","acceptedAnswer":{"@type":"Answer","text":"It displays fake browser update prompts that instruct victims to manually execute attacker-provided commands, tricking users into running malicious code themselves. This was one of several modules deployed by a malware framework distributed through compromised Chrome and Edge extensions, alongside credential theft, session hijacking, and browser history exfiltration. daily.dev helps developers stay ahead of social-engineering tactics like ClickFix targeting end users."}}]}
```

