Malicious Chrome and Edge browser-extension campaign
Campaign
Summary
Hide ▲
Show ▼
A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto theft, credential theft, and browser-history exfiltration. The operation appears to have been active since early 2024, and one extension reached 70,000 Chrome users and 10,000 Edge installs before turning malicious. The campaign matters because its modular design and automatic-update abuse let attackers scale payload delivery across multiple extensions.
Related Happenings
Superior malicious extension installation campaign
Campaign
H score17
First: 28.08.2026 18:27
Last: 28.08.2026 18:27
Sources 1
How related:
According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically.
About this happening:
The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Superior malicious extension installation campaign
CampaignHow related: According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically.
About this happening: The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrom...
Silent Swap browser-extension clipboard clipper
Malware Activity
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension clipboard clipper
Malware ActivityAbout this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Commercial adware and traffic-attribution-fraud affiliate operation using Chrome extensions
Threat Actor Meta
H score20
First: 15.06.2026 14:07
Last: 15.06.2026 14:07
Sources 1
About this happening:
Researchers found a commercial adware and traffic-attribution-fraud affiliate operation abusing Chrome extensions to fabricate traffic signals and monetize installs, i...
Commercial adware and traffic-attribution-fraud affiliate operation using Chrome extensions
Threat Actor MetaAbout this happening: Researchers found a commercial adware and traffic-attribution-fraud affiliate operation abusing Chrome extensions to fabricate traffic signals and monetize installs, i...
Timeline
-
30.08.2026 17:17 2 articles · 2h ago
Socket uncovers malicious Chrome and Edge extension campaign
Initial DisclosureSocket uncovered a campaign in which multiple Google Chrome and Microsoft Edge extensions delivered a modular malware framework that stole cryptocurrency, sensitive data, and browser history, injected ClickFix lures, and stripped Content Security Policy (CSP) headers from visited sites. The investigation indicates the operation may have been active since early 2024, and Google removed one affected extension from the Chrome Web Store while the Edge version remained available; other malicious extensions were no longer available in the Chrome Web Store.
Show sources
- Chrome Web Store extensions caught stealing crypto, browser data — www.bleepingcomputer.com — 30.08.2026 17:17
- Chrome Web Store extensions caught stealing crypto, browser data — www.bleepingcomputer.com — 30.08.2026 17:17