Executive Summary
In August 2026, security researchers at Socket uncovered a sophisticated malware campaign targeting Chrome and Edge browser extensions that had been active since early 2024. Nineteen malicious modules were deployed through initially legitimate extensions, some acquired from original creators and weaponized through automatic updates. The most notable example was the "Enable Right Click & Copy" extension with over 70,000 Chrome users and 10,000 Edge users. The malware established encrypted WebSocket connections to command-and-control servers, removed Content Security Policy headers, and deployed modules capable of draining cryptocurrency wallets, stealing credentials from major exchanges like Coinbase and Binance, harvesting social media data, and deploying ClickFix-style phishing attacks.
This incident highlights the growing sophistication of supply chain attacks targeting browser ecosystems, coinciding with increased regulatory scrutiny of app store security practices and the rise of cryptocurrency-focused cybercrime operations that leverage trusted distribution channels.
Why This Matters Now
Browser extension supply chain attacks are escalating as threat actors exploit the trust users place in established extensions, targeting cryptocurrency assets worth billions while app stores struggle to implement effective post-publication monitoring.
Attack Path Analysis
Attackers distributed malicious browser extensions through Chrome Web Store and Edge add-ons marketplace, initially providing legitimate functionality before injecting malware via updates. The extensions established encrypted WebSocket connections to C2 servers, downloaded JavaScript modules, and deployed 19 distinct malware modules to steal cryptocurrency wallets, browser data, credentials, and deploy ClickFix lures. Victims had their crypto assets drained, credentials harvested, and were exposed to additional social engineering attacks through fake browser updates.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Malicious browser extensions distributed via Chrome Web Store and Edge marketplace, some acquired from legitimate developers and weaponized through automatic updates
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Browser Extensions
Credentials from Password Stores: Credentials from Web Browsers
Application Layer Protocol: Web Protocols
Encrypted Channel: Symmetric Cryptography
Browser Session Hijacking
Steal Web Session Cookie
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Application Security
Control ID: Applications and Workloads
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Chrome extensions stole cryptocurrency wallets, banking credentials from major exchanges like Coinbase, Binance, requiring immediate credential resets and wallet migrations.
Computer Software/Engineering
Malicious browser extensions bypassed security policies, injected scripts, and established C2 connections, exposing development environments and corporate credentials to theft.
Marketing/Advertising/Sales
Extensions harvested Facebook and LinkedIn account data while displaying fake ad spy tools, compromising social media marketing accounts and customer data.
Internet
Web-based businesses face credential theft, session hijacking, and browser history exfiltration through compromised extensions affecting user trust and data security.
Sources
- Chrome Web Store extensions caught stealing crypto, browser datahttps://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/Verified
- Chrome and Edge Extensions Hijacking Cryptocurrency Walletshttps://socket.dev/blog/chrome-edge-extension-wallet-drainerVerified
- Malicious Browser Extensions Steal Crypto and Personal Datahttps://thehackernews.com/2024/08/malicious-browser-extensions-steal.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the malicious browser extension campaign by limiting C2 communications and reducing lateral spread across cloud workloads. Zero Trust segmentation could have reduced the blast radius of credential harvesting and cryptocurrency theft operations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud workloads hosting related infrastructure would likely have been subject to identity-aware access controls and segmented network boundaries, potentially limiting the scope of extension deployment coordination.
Control: Zero Trust Segmentation
Mitigation: Browser-based privilege escalation would likely have faced constrained network reachability to cloud resources, limiting the attacker's ability to expand access beyond initial compromise points through segmented boundaries.
Control: East-West Traffic Security
Mitigation: Lateral movement between cloud workloads would likely have been constrained by east-west traffic inspection and segmentation policies, reducing the attacker's ability to spread malicious payloads across interconnected systems.
Control: Multicloud Visibility & Control
Mitigation: C2 communications would likely have faced visibility constraints and policy enforcement across multicloud environments, potentially limiting the attacker's ability to maintain persistent command channels and payload delivery mechanisms.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration paths would likely have been constrained by egress security policies and controlled outbound access, potentially limiting the volume and scope of stolen cryptocurrency and credential data leaving the environment.
While some cryptocurrency theft and credential compromise would likely still occur, the overall impact scope would be reduced through constrained network access and limited attacker reachability to additional victim systems.
Impact at a Glance
Affected Business Functions
- Cryptocurrency Trading
- Digital Asset Management
- Browser-based Authentication
- Online Financial Services
Estimated downtime: N/A
Estimated loss: N/A
Cryptocurrency wallet credentials and seed phrases from multiple platforms including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. Browser history, login credentials, form data, and Facebook/LinkedIn account information for approximately 80,000 users across Chrome and Edge platforms.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security and policy enforcement to detect and block unauthorized outbound connections from browser extensions to suspicious C2 domains
- • Deploy multicloud visibility and control solutions to monitor anomalous WebSocket connections and repeated malformed requests across cloud environments
- • Establish zero trust segmentation policies to limit browser extension privileges and prevent lateral movement across web applications
- • Utilize threat detection and anomaly response capabilities to baseline normal browser behavior and alert on suspicious extension activities
- • Enforce encrypted traffic inspection through inline IPS capabilities to identify malicious payload downloads and C2 communication patterns



