19 Chrome and Edge Extensions Were Caught Stealing Login Data and Crypto Tokens

news
19 Chrome and Edge Extensions Were Caught Stealing Login Data and Crypto Tokens

Security researchers have identified 19 browser extensions for Google Chrome and Microsoft Edge that contained malicious code capable of stealing sensitive information.

The affected add ons were available through official browser stores and appeared to perform legitimate functions. Some focused on search tools, right click controls, SEO analysis, advertising research, or cryptocurrency tracking.

The problem came later. After the extensions had built up trust and installations, malicious code was added that could collect browser history, login information, and cryptocurrency related tokens.

Google and Microsoft have removed the affected extensions from their stores, but people who already installed them may still need to remove them manually.

DetailInformation
Number of affected extensions19
Browsers affectedGoogle Chrome and Microsoft Edge
Main risksLogin theft, browser history collection, crypto token theft
Store statusRemoved from official stores
User action requiredManual uninstall if already installed
Largest known install baseAround 70,000
Campaign durationReportedly active for about two years

One Extension Had Around 70,000 Installations

The most widely used extension in the group was Enable Right Click & Copy, Smart Unlock + OCR.

It reportedly reached around 70,000 installations before being removed.

The extension was capable of useful functions, which helped it appear legitimate. The malicious component was later introduced through a backdoor and could collect sensitive browser information without obvious signs that anything was wrong.

That included browsing history, login credentials, and cryptocurrency tokens.

Because browser extensions often have broad access to web pages and browser activity, malicious code inside one can create serious privacy and security risks.

Some Extensions Were Built by the Attackers

The campaign did not rely on only one method.

Around 14 of the 19 extensions were reportedly created directly by the attackers. The remaining five were originally built by other developers and were later acquired.

That approach allowed the attackers to take advantage of extensions that already had an established install base or reputation.

Most of the extensions initially targeted Chrome. Edge versions were added later.

The malicious campaign reportedly remained active for around two years without attracting widespread attention.

These Extensions Should Be Removed

The affected extensions include:

Enable Right Click & Copy, Smart Unlock + OCR
RapidLens, Google Lens for Screen Search & Images
QuickLens, Search Screen with Google Lens
Password Protect PDF
Allow Copy, Select & Enable Right Click
PixelCheck
Creative Library, Ad Spy Tool
Website Traffic Checker: MirrorSphere SEO Stats
Site Signal, Website Traffic & SEO Checker
SEO Pulse Pro, Website Traffic & SEO Analyser
Private Crypto News Reader
Blockfolio: Address Monitor
Crypto Rates & Fiat Converter
Crypto Alerter: Price Alerts & Volatility Warnings
DeFi Pulse Tracker
Crypto Price Badge: Quick Glance
Multi Chain Explorer
LedgerLook: Wallet Checker
Meta & Facebook Ad Library Spy, Save Ads, Finder, Downloader, FeedX Ray

If any of these extensions are installed in your browser, they should be removed immediately.

Store Removal Does Not Automatically Fix the Problem

One important issue is that removal from the Chrome Web Store or Edge Add ons store does not necessarily uninstall an extension that is already present on your computer.

That means the malicious software could remain active until you manually remove it.

You should also review the extensions currently installed in your browser, especially ones that have not been updated recently or are no longer listed in the official store.

For accounts that may have been exposed, changing passwords and reviewing active sessions is also sensible. Cryptocurrency wallet credentials and tokens deserve particular attention because they can be used to access digital assets.

The incident is another reminder that being listed in an official browser store does not guarantee that an extension will remain safe forever.

A legitimate extension can be sold, compromised, or updated with malicious code after people have already installed it.

Regularly reviewing installed add ons, removing anything you no longer use, and limiting extensions to tools you genuinely need can reduce that risk.

Discover: News

Discussion (0)

Be the first to comment.