Security1 distinct publisher3 min readPublished Updated
Socket says the operators bought their way onto tens of thousands of machines and delivered the payload in a routine update. Cleanup means rotating passwords and moving crypto to fresh wallets, user by user.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The purchase is the load-bearing step. Socket says five of the extensions were acquired from their original creators and then injected with malware through updates the browser applied automatically [5]. No developer account had to be cracked, and the listing kept whatever trust it earned while it was doing the job it advertised [4]. For a defender, the approval event and the compromise event are separated by a version number.
The runtime is built to survive review. Each install opens an encrypted WebSocket to command and control and pulls JavaScript modules down from there [8], so the code that steals does not have to sit in the package a store looked at. Once running, the framework removes Content Security Policy headers from every website the victim visits and injects scripts through hidden HTML elements [8]. That is first-party execution on arbitrary pages, which explains the module inventory: Socket counted 16 modules, each with a distinct purpose and built to be extensible [2]. Wallet drainers hijack legitimate Connect Wallet and Swap buttons on EVM, Solana and Tron [9]. Ledger and Trezor sites are replaced with seed-phrase phishing pages [10]. Session, token, account and balance theft covers Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit and MetaMask [11]. Credentials and form entries are recorded across sites, Facebook and LinkedIn account data is harvested, and browsing history is exfiltrated [12]. ClickFix-style fake update prompts push the victim into running attacker-supplied commands, which takes the operator off the page and onto the host [13].
Scope, as published: the dual-listed extension had at least 70,000 Chrome users and 10,000 Edge installs at the moment it turned [6], a floor of 80,000 [18] on one of the five acquired listings. Those are the only install figures given [19]. Treat 80,000 as the counted part.
Google removed the Chrome listing early, and by the time Socket published, none of the campaign's extensions remained in the Chrome Web Store [7][15]. The Edge build of that same extension was still available [7]. Same code, two marketplaces, one takedown.
Remediation does not look like patching. Socket's guidance to anyone who ran one of these is to assume credentials are compromised, change passwords, and move crypto holdings to a newly created wallet [17]. That work scales with the install base, not with the number of malicious versions shipped.
The report publishes the extension IDs and the C2 domains [16], which supports two queries: installed IDs across the fleet, and egress to those domains. Socket expects further modules as the framework evolves [14], so the domain list ages faster than the ID list. Useful inventory is keyed to extension ID and installed version, because an approval date describes code that may no longer be the code running.
Ranked by verification strength, evidence, and original report placement.
Multiple Chrome and Edge extensions delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data and browser history and to inject ClickFix lures; the operation was uncovered by application security company Socket.
Researchers say all 16 malicious modules uncovered in the campaign serve distinct purposes and are designed to be highly extensible.
Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware.
According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically.
The extension "Enable Right Click & Copy - Smart Unlock + OCR" was the only one in the campaign available for both Chrome and Edge; it had a Chrome user base of at least 70,000 when it turned malicious, and 10,000 installs on Edge at the time.
Google caught the threat early and removed the extension from the Chrome add-ons marketplace, but at the time Socket published its report the Edge version remained available.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Superior ships its wallet drainer as a routine auto-update to extensions users already trusted1 distinct publisher
build
Chrome's auto-update default distributed the drainer once the extension changed hands1 distinct publisher
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
product
Fake Codex installer outranks OpenAI in Google ads, then asks for a paste1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's findings, told once
The mechanism is described with the kind of specificity that is hard to fake — encrypted WebSocket C2, CSP headers stripped per site, modules injected through hidden elements — and Socket published extension IDs and C2 domains anyone can check. What is missing is anyone else in the room: no second researcher, no Google or Microsoft confirmation of the removals, and a start date carried as "may have been active since early 2024" with nothing shown that dates it.
Reach measured on exactly one listing
Real-world footprint here is one number doing all the work: roughly 80,000 machines across Chrome and Edge for the OCR extension. Four other acquired extensions are counted but never sized, no victim tally exists, and no funds are traced. The takedowns are the firmest evidence of consequence — Chrome cleared, Edge still serving at report time.
Capabilities catalogued, damage uncounted
The bullet list reads like a wallet-drainer greatest hits — three chains, eight exchanges, hardware-wallet seed phishing — while the confirmed footprint is one extension's 80,000 installs and zero measured theft. BleepingComputer does not embellish; it just reports the capability catalogue as Socket wrote it, and "observed modules" quietly becomes the scale of the story. The dek's "tens of thousands of machines" is the floor figure used honestly, which keeps the stretch modest rather than serious.
Disclosure that doubles as a sales asset
Socket sells application security, and a named campaign with 16 modules and a crypto angle is the kind of finding that markets the product; nothing in the technical work looks bent by that, but the framing and the module count are the vendor's to set. BleepingComputer's own page closes with a pitch for a sponsored security report — the commercial layer sits directly beneath the remediation advice, in plain sight.
Firm on mechanism, thin on scope
Treat the how as reliable and the how-much as open. The attack chain, the buyout-then-auto-update route and the published indicators are specific enough to act on today; the number of extensions, the number of victims, the 2024 origin and the reason Edge lagged Chrome all wait on either Socket's underlying report or a platform statement that no one has yet given.