Malicious Browser Extensions Steal Crypto, Sensitive Data in Massive Campaign
A malicious campaign has been uncovered by researchers at Socket, targeting users of Google Chrome and Microsoft Edge through compromised browser extensions.
The operation, which may have started as early as 2024, involved 16 extensions that delivered a malware framework with various modules designed to steal cryptocurrency, sensitive data, and browser history.
According to Socket, five of the extensions were acquired from their original creators and infected with malware via automatic updates. One example is the 'Enable Right Click & Copy, Smart Unlock + OCR' extension, which had at least 70,000 users on Chrome and 10,000 on Edge when it turned malicious.
The malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from visited websites, and injects malicious scripts into websites through hidden HTML elements.