<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso" -->

---
title: Trusted Chrome, Edge extensions weaponized in supply...
description: Researchers at Socket uncovered a supply chain campaign involving 19 Chrome and Edge extensions weaponized after being acquired from legitimate publishers or...
canonical: https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Trusted Chrome, Edge extensions weaponized in supply chain campaign | daily.dev
og:description: Researchers at Socket uncovered a supply chain campaign involving 19 Chrome and Edge extensions weaponized after being acquired from legitimate publishers or...
og:url: https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso
og:image: https://api.daily.dev/og/posts/QLFUJSXSO.png
og:image:alt: Trusted Chrome, Edge extensions weaponized in supply chain campaign
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Trusted Chrome, Edge extensions weaponized in supply chain campaign

**[CSO Online](https://daily.dev/sources/csoonline)** · 5 min read · 0 upvotes · 0 comments

## Summary

Researchers at Socket uncovered a supply chain campaign involving 19 Chrome and Edge extensions weaponized after being acquired from legitimate publishers or built clean before later receiving malicious updates. One extension, Enable Right Click & Copy, had roughly 70,000 users when malicious code was injected. The malware could strip Content Security Policy headers, inject attacker-supplied JavaScript, steal form data, hijack browser sessions, and target social media accounts, with cryptocurrency theft as the main focus. The campaign traces back to February 2024 activity linked by DomainTools. Security experts recommend treating extensions as continuously changing third-party software requiring lifecycle monitoring rather than one-time install approval, since existing endpoint and network tools like EDR and SWG provide limited visibility into in-browser extension behavior.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4215792/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign.html>

## Questions this post answers

### How did attackers turn legitimate Chrome and Edge extensions into malware?

Attackers acquired five previously legitimate extensions from their original publishers and later pushed malicious updates to existing users, while also releasing 14 clean extensions of their own that turned malicious only after gaining users. Because browser extensions update automatically, malicious code reached users without any new download or reinstall, affecting a campaign of 19 extensions total.

_Security teams tracking browser extension supply chain risks can follow developments like this on daily.dev._

### What could the malicious browser extensions in the Socket-discovered campaign actually do once installed?

The malware could contact attacker-controlled servers to fetch additional JavaScript payloads, strip Content Security Policy headers from visited websites to allow injected code to run, capture data typed into web forms, steal authentication material from active sessions, and target logged-in social media accounts along with browsing history, primarily for cryptocurrency theft.

_Anyone assessing browser-based attack surfaces can stay current on extension threats via daily.dev._

### Why don't EDR and SWG tools catch malicious browser extension activity?

EDR, SWG, SASE, and managed browser tools generally lack visibility into extension-level behavior such as DOM access, CSP tampering, script injection, or token capture, since these actions happen inside the browser rather than through a conventional executable on the endpoint. Incorporating browser telemetry into MDR monitoring can help close that visibility gap.

_Enterprise defenders weighing browser telemetry gaps can track this angle through daily.dev._

## Similar posts on daily.dev

- [Newly discovered malicious extensions could be lurking in enterprise browsers](https://daily.dev/posts/newly-discovered-malicious-extensions-could-be-lurking-in-enterprise-browsers-i20gceevx) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#devtools](https://daily.dev/tags/devtools), [#malware](https://daily.dev/tags/malware), [#google-chrome](https://daily.dev/tags/google-chrome)

[View this post on daily.dev](https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Trusted Chrome, Edge extensions weaponized in supply chain campaign","url":"https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso"},"datePublished":"2026-08-31T09:49:27.187Z","dateModified":"2026-08-31T10:10:43.974Z","description":"Researchers at Socket uncovered a supply chain campaign involving 19 Chrome and Edge extensions weaponized after being acquired from legitimate publishers or...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5090b2e78d869fb4fae28beb0dc9f9b6?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5090b2e78d869fb4fae28beb0dc9f9b6?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,devtools,malware,google-chrome","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Trusted Chrome, Edge extensions weaponized in supply chain campaign"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign-qlfujsxso#faq","mainEntity":[{"@type":"Question","name":"How did attackers turn legitimate Chrome and Edge extensions into malware?","acceptedAnswer":{"@type":"Answer","text":"Attackers acquired five previously legitimate extensions from their original publishers and later pushed malicious updates to existing users, while also releasing 14 clean extensions of their own that turned malicious only after gaining users. Because browser extensions update automatically, malicious code reached users without any new download or reinstall, affecting a campaign of 19 extensions total. Security teams tracking browser extension supply chain risks can follow developments like this on daily.dev."}},{"@type":"Question","name":"What could the malicious browser extensions in the Socket-discovered campaign actually do once installed?","acceptedAnswer":{"@type":"Answer","text":"The malware could contact attacker-controlled servers to fetch additional JavaScript payloads, strip Content Security Policy headers from visited websites to allow injected code to run, capture data typed into web forms, steal authentication material from active sessions, and target logged-in social media accounts along with browsing history, primarily for cryptocurrency theft. Anyone assessing browser-based attack surfaces can stay current on extension threats via daily.dev."}},{"@type":"Question","name":"Why don't EDR and SWG tools catch malicious browser extension activity?","acceptedAnswer":{"@type":"Answer","text":"EDR, SWG, SASE, and managed browser tools generally lack visibility into extension-level behavior such as DOM access, CSP tampering, script injection, or token capture, since these actions happen inside the browser rather than through a conventional executable on the endpoint. Incorporating browser telemetry into MDR monitoring can help close that visibility gap. Enterprise defenders weighing browser telemetry gaps can track this angle through daily.dev."}}]}
```

