"designed to be 'highly extensible,'" Socket said.
Socket's investigation and timeline
Application security company Socket uncovered a multi-extension campaign that delivered a modular malware framework to Chrome and Edge users and says the operation may have been active since early 2024. Socket identified that 16 distinct malicious modules were used in the campaign, each serving a specific purpose. When the extensions were first published on the Chrome Web Store, many delivered legitimate advertised functionality and contained no malware; Socket reports that five extensions were later acquired from their original creators and injected with malicious updates delivered automatically to users.
Extension distribution and a large example
Socket named specific extensions and provided the full list of extension IDs and the domains used for command-and-control (C2) communication in its report. One high-profile example is "Enable Right Click & Copy — Smart Unlock + OCR," the only extension in the campaign available on both Chrome and Edge. According to Socket, the Chrome version had a user base of at least 70,000 at the time it turned malicious, and the Edge version had about 10,000 installs. Google removed the extension from the Chrome Web Store after detecting the threat; Socket noted that at the time it published its report the Edge version remained available.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleMalware behavior: C2, CSP removal, script injection, and 16 modules
After installation, the malicious extensions establish an encrypted WebSocket connection to C2 servers and download JavaScript modules. The payloads remove Content Security Policy (CSP) headers from every website a victim visits and inject malicious scripts into pages using hidden HTML elements. Socket observed modules performing a range of functions and warned the framework may include additional modules that could be deployed over time.
- Draining EVM, Solana, and Tron wallets by hijacking legitimate "Connect Wallet" and "Swap" buttons
- Replacing Ledger and Trezor websites with convincing seed-phrase phishing pages
- Stealing sessions, tokens, account data, and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask
- Recording credentials and form entries across websites
- Harvesting Facebook and LinkedIn account information
- Exfiltrating browser history
- Displaying ClickFix-style fake browser updates that instruct victims to execute attacker-provided commands
Immediate remediation Socket recommends
Socket advises that users who had any of the extensions installed should assume their credentials have been compromised and change their login passwords. For cryptocurrency holders potentially impacted by the campaign, Socket recommends moving assets to a newly created wallet as soon as possible. Socket also warns the malicious framework may evolve and deploy new payloads over time, increasing the urgency of remediation.
What this means for cryptocurrency holders, browser users, and security teams
Cryptocurrency holders: The malware contains modules specifically built to drain wallets on EVM, Solana, and Tron chains and to hijack legitimate wallet interactions; victims with browser-based wallets or who use browser wallet connect flows should assume exposure and, per Socket, move assets to new wallets immediately.
Browser users: Several extensions began life as legitimate tools and were altered after acquisition; users should review installed extensions and remove anything they do not recognize. Socket's finding that CSP headers are removed and malicious scripts are injected means routine browsing sessions could have been monitored or manipulated without visible signs.
Security teams and defenders: Socket provided extension IDs and C2 domains in its report; defenders can use those indicators to hunt for infections. The report also notes that prevention effectiveness can fall once attackers possess valid credentials — a point reinforced by Socket's reference to the Blue Report 2026, which measures defenses technique-by-technique across 338 million simulations run in customer environments.
The campaign illustrates a straightforward but effective attack path: extensions that begin as legitimate tools can be weaponized via ownership changes and automatic updates, then used to deliver a multi-module framework that targets digital wallets, exchanges, social accounts, and browser histories. Socket warns the framework may hold more modules and will likely evolve, leaving a concrete question for platform operators and users: how many other extensions with large user bases might be hijacked and updated to perform the same range of theft and deception?




