Abstract:
Security researchers recently discovered that a multi-year malicious campaign is using the Chrome extension system to attack users. Cybercriminals have implanted malicious code into multiple browser extensions, affecting tens of thousands of devices. Even if the relevant extension has been removed from the app store, users may still be at risk if they do not manually check and adjust browser configurations.

Researchers from Socket found a total of 19 malicious extensions targeting Chrome and Edge users. Although the attack campaign mainly targets Google Chrome, one of the extensions has gained high popularity on both Chrome and Edge. Researchers believe that these attacks are likely to be operated by the same criminal group, and even though the relevant extensions have been removed from the two major browser stores, the people behind them are still trying to maintain the attack activity.
Socket stated that these malicious extensions use similar attack methods. 14 of them were developed directly by cybercriminals, and the other 5 were purchased from legitimate developers or companies. The extension was initially able to provide its advertised functionality, but over the past six months, hackers have updated the extension to insert malicious code into it to invade user systems or collect user data.
Among the affected extensions, one tool called "Enable Right Click & Copy - Smart Unlock + OCR" is particularly popular. It was installed on approximately 70,000 Chrome browsers and 10,000 Edge browsers, ultimately exposing a total of approximately 80,000 users to risk. This extension mainly targets cryptocurrency wallets and other cryptocurrency-related data.

Researchers said the attackers used some code-based attack patterns that were first discovered in February 2024. They wait for the extension to accumulate enough potential victims before remotely delivering the malicious payload and managing the cryptocurrency theft through a flexible command-and-control domain infrastructure.
Currently, these 19 malicious extensions have been removed from the Chrome and Edge app stores. However, if users do not review and manually remove all 19 extensions listed by the researchers, the relevant devices may still remain in contact with the attacker's command and control infrastructure and therefore continue to be at risk.
Google announced in 2018 that it would make major adjustments to the extension technology used by the Chromium project. The Manifest V3 API, launched for Chromium-based browsers such as Chrome and Microsoft Edge, was originally designed to improve the security architecture of browser extensions.
However, these 19 extensions that have been re-implanted with malicious payloads show that technical architecture upgrades alone cannot completely prevent such attacks. Even if Manifest V2 is eventually retired, cybercriminals may continue to target popular browser extensions.
Comments