Skip to content
Back to Guavy Wire
Crypto

Malicious Browser Extensions Steal Crypto, Sensitive Data in Massive Campaign

Instruments
MEW
Share

A malicious campaign has been uncovered by researchers at Socket, targeting users of Google Chrome and Microsoft Edge through compromised browser extensions.

The operation, which may have started as early as 2024, involved 16 extensions that delivered a malware framework with various modules designed to steal cryptocurrency, sensitive data, and browser history.

According to Socket, five of the extensions were acquired from their original creators and infected with malware via automatic updates. One example is the 'Enable Right Click & Copy, Smart Unlock + OCR' extension, which had at least 70,000 users on Chrome and 10,000 on Edge when it turned malicious.

The malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from visited websites, and injects malicious scripts into websites through hidden HTML elements.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc