Routine updates turn seemingly harmless browser extensions into malware delivery systems

Research reveals that benign-looking Chrome and Edge extensions can covertly become vectors for malware after routine updates, targeting millions of users with credential theft and browser spying techniques.

Browser extensions that appear harmless for months can still be turned into delivery systems for malware after a routine update, according to research cited by Clubic and the application security firm Socket. In the latest campaign, extensions for Google Chrome and Microsoft Edge were altered only after they had already built a sizeable user base, giving attackers a ready-made audience before the malicious code was activated.

One example, “Enable Right Click & Copy , Smart Unlock + OCR”, had about 70,000 Chrome installations and a further 10,000 on Edge when the harmful code was introduced, Clubic reported. That approach echoes a pattern seen previously in the Chromium ecosystem, where extensions first win trust as legitimate tools and later receive updates that add hostile behaviour.

Once compromised, the extension opened an encrypted link to attacker-controlled servers and could receive JavaScript modules on demand. Socket said it observed 16 such modules, used for credential theft, browser spying and cryptocurrency theft. They could hijack wallet login or exchange buttons, display fake Ledger and Trezor pages, steal active sessions from services such as Coinbase, Binance, Kraken and MetaMask, capture usernames and passwords, and collect browsing history.

The code could also tamper with the web pages themselves by disabling Content Security Policy, the browser control that limits which scripts a site may load and run. That would let attackers inject their own content, including fake browser-update prompts modelled on ClickFix techniques, and trick victims into running malicious commands themselves. Earlier research has shown similar tactics in malicious extension campaigns: Kaspersky found Chrome add-ons abusing ChatGPT branding to steal Facebook cookies in 2023, while Malwarebytes reported in January 2026 on extensions that stole ChatGPT session tokens. Cybernews also documented a large April 2026 campaign in which dozens of Chrome extensions funnelled stolen data to a single operator, underlining how persistent the threat has become.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.