Security researchers have identified 19 browser extensions for Google Chrome and Microsoft Edge that contained malicious code capable of stealing sensitive information.
The affected add ons were available through official browser stores and appeared to perform legitimate functions. Some focused on search tools, right click controls, SEO analysis, advertising research, or cryptocurrency tracking.
The problem came later. After the extensions had built up trust and installations, malicious code was added that could collect browser history, login information, and cryptocurrency related tokens.
Google and Microsoft have removed the affected extensions from their stores, but people who already installed them may still need to remove them manually.
| Detail | Information |
|---|---|
| Number of affected extensions | 19 |
| Browsers affected | Google Chrome and Microsoft Edge |
| Main risks | Login theft, browser history collection, crypto token theft |
| Store status | Removed from official stores |
| User action required | Manual uninstall if already installed |
| Largest known install base | Around 70,000 |
| Campaign duration | Reportedly active for about two years |
One Extension Had Around 70,000 Installations
The most widely used extension in the group was Enable Right Click & Copy, Smart Unlock + OCR.
It reportedly reached around 70,000 installations before being removed.
The extension was capable of useful functions, which helped it appear legitimate. The malicious component was later introduced through a backdoor and could collect sensitive browser information without obvious signs that anything was wrong.
That included browsing history, login credentials, and cryptocurrency tokens.
Because browser extensions often have broad access to web pages and browser activity, malicious code inside one can create serious privacy and security risks.
Some Extensions Were Built by the Attackers
The campaign did not rely on only one method.
Around 14 of the 19 extensions were reportedly created directly by the attackers. The remaining five were originally built by other developers and were later acquired.

That approach allowed the attackers to take advantage of extensions that already had an established install base or reputation.
Most of the extensions initially targeted Chrome. Edge versions were added later.
The malicious campaign reportedly remained active for around two years without attracting widespread attention.
These Extensions Should Be Removed
The affected extensions include:
Enable Right Click & Copy, Smart Unlock + OCR
RapidLens, Google Lens for Screen Search & Images
QuickLens, Search Screen with Google Lens
Password Protect PDF
Allow Copy, Select & Enable Right Click
PixelCheck
Creative Library, Ad Spy Tool
Website Traffic Checker: MirrorSphere SEO Stats
Site Signal, Website Traffic & SEO Checker
SEO Pulse Pro, Website Traffic & SEO Analyser
Private Crypto News Reader
Blockfolio: Address Monitor
Crypto Rates & Fiat Converter
Crypto Alerter: Price Alerts & Volatility Warnings
DeFi Pulse Tracker
Crypto Price Badge: Quick Glance
Multi Chain Explorer
LedgerLook: Wallet Checker
Meta & Facebook Ad Library Spy, Save Ads, Finder, Downloader, FeedX Ray
If any of these extensions are installed in your browser, they should be removed immediately.
Store Removal Does Not Automatically Fix the Problem
One important issue is that removal from the Chrome Web Store or Edge Add ons store does not necessarily uninstall an extension that is already present on your computer.
That means the malicious software could remain active until you manually remove it.
You should also review the extensions currently installed in your browser, especially ones that have not been updated recently or are no longer listed in the official store.
For accounts that may have been exposed, changing passwords and reviewing active sessions is also sensible. Cryptocurrency wallet credentials and tokens deserve particular attention because they can be used to access digital assets.
The incident is another reminder that being listed in an official browser store does not guarantee that an extension will remain safe forever.
A legitimate extension can be sold, compromised, or updated with malicious code after people have already installed it.
Regularly reviewing installed add ons, removing anything you no longer use, and limiting extensions to tools you genuinely need can reduce that risk.



Discussion (0)
Be the first to comment.