
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures.
Researchers say all 16 malicious modules uncovered in the campaign serve distinct purposes and are designed to be “highly extensible.”
The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024.
Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware.
According to the researchers, five of the extensions were acquired from their original…







