Chrome Web Store extensions caught stealing crypto, browser data
6 Articles
6 Articles
Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
Malicious browser extensions used stores as initial access
Researchers at Socket identified 19 malicious modules delivered through Chrome and Edge extensions, some of them originally benign or acquired from legitimate developers. The framework used encrypted WebSocket C2, stripped CSP protections...
Browser Extensions as Wallet Thieves: How a Sports App Became a Seed Phrase Collector
If you run a crypto wallet as a browser extension, today is the day to open your extension list. In August 2026 the security firm Socket disclosed two separate campaigns in which extensions for Firefox, Chrome and Edge harvested recovery phrases, private keys and login credentials for crypto...
Security company Socket released two separate campaigns in August 2026: 40 confirms malicious Firefox extensions and 19 for Chrome and Edge, all from official marketplaces. Nine of them were previously harmless sports apps that were only updated to become a wallet thief.
Nineteen extensions designed to steal cryptocurrency data have been discovered in Google Chrome and Microsoft Edge. The list includes tools that can hijack seed phases, login credentials for exchange services, and cryptocurrency wallets. Full version of the page: https://ithardware.pl/aktualnosci/google_chrome_microsoft_edge_niebezpieczne_wtyczki-53626.html
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium









