Executive Summary

In August 2026, security researchers at Socket uncovered a sophisticated malware campaign targeting Chrome and Edge browser extensions that had been active since early 2024. Nineteen malicious modules were deployed through initially legitimate extensions, some acquired from original creators and weaponized through automatic updates. The most notable example was the "Enable Right Click & Copy" extension with over 70,000 Chrome users and 10,000 Edge users. The malware established encrypted WebSocket connections to command-and-control servers, removed Content Security Policy headers, and deployed modules capable of draining cryptocurrency wallets, stealing credentials from major exchanges like Coinbase and Binance, harvesting social media data, and deploying ClickFix-style phishing attacks.

This incident highlights the growing sophistication of supply chain attacks targeting browser ecosystems, coinciding with increased regulatory scrutiny of app store security practices and the rise of cryptocurrency-focused cybercrime operations that leverage trusted distribution channels.

Why This Matters Now

Browser extension supply chain attacks are escalating as threat actors exploit the trust users place in established extensions, targeting cryptocurrency assets worth billions while app stores struggle to implement effective post-publication monitoring.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The extensions initially provided legitimate functionality and only became malicious after threat actors acquired them from original creators and pushed weaponized updates through automatic extension update mechanisms.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained the malicious browser extension campaign by limiting C2 communications and reducing lateral spread across cloud workloads. Zero Trust segmentation could have reduced the blast radius of credential harvesting and cryptocurrency theft operations.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud workloads hosting related infrastructure would likely have been subject to identity-aware access controls and segmented network boundaries, potentially limiting the scope of extension deployment coordination.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Browser-based privilege escalation would likely have faced constrained network reachability to cloud resources, limiting the attacker's ability to expand access beyond initial compromise points through segmented boundaries.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between cloud workloads would likely have been constrained by east-west traffic inspection and segmentation policies, reducing the attacker's ability to spread malicious payloads across interconnected systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communications would likely have faced visibility constraints and policy enforcement across multicloud environments, potentially limiting the attacker's ability to maintain persistent command channels and payload delivery mechanisms.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration paths would likely have been constrained by egress security policies and controlled outbound access, potentially limiting the volume and scope of stolen cryptocurrency and credential data leaving the environment.

Impact (Mitigations)

While some cryptocurrency theft and credential compromise would likely still occur, the overall impact scope would be reduced through constrained network access and limited attacker reachability to additional victim systems.

Impact at a Glance

Affected Business Functions

  • Cryptocurrency Trading
  • Digital Asset Management
  • Browser-based Authentication
  • Online Financial Services
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Cryptocurrency wallet credentials and seed phrases from multiple platforms including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. Browser history, login credentials, form data, and Facebook/LinkedIn account information for approximately 80,000 users across Chrome and Edge platforms.

Recommended Actions

  • Implement egress security and policy enforcement to detect and block unauthorized outbound connections from browser extensions to suspicious C2 domains
  • Deploy multicloud visibility and control solutions to monitor anomalous WebSocket connections and repeated malformed requests across cloud environments
  • Establish zero trust segmentation policies to limit browser extension privileges and prevent lateral movement across web applications
  • Utilize threat detection and anomaly response capabilities to baseline normal browser behavior and alert on suspicious extension activities
  • Enforce encrypted traffic inspection through inline IPS capabilities to identify malicious payload downloads and C2 communication patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image