← Back to overview

Socket has expanded its browser extension security coverage to Microsoft Edge, enabling enterprise security teams to detect malware, credential theft, suspicious network activity, and risky updates across Edge extensions. Research uncovered 18 malicious Chrome extensions and one Edge extension delivering an extensible malware framework, with five purchased from legitimate developers and turned malicious via updates. One purchased extension had ~70,000 Chrome users and 10,000 Edge users when malicious functionality appeared. After Chrome removed the listing, the Edge version remained active and was updated with a new C2 domain on August 14, 2026. The malware included 16 modules: a multi-chain wallet drainer, Ledger/Trezor phishing, credential theft, session harvesting, browser-history exfiltration, and a fake Chrome update. Socket now provides continuous analysis across Chrome, Firefox, and Edge extension ecosystems, monitoring version changes, permissions, network activity, and related campaigns.

Technical details

Socket researchers identified 18 malicious Chrome extensions and one Edge extension delivering an extensible malware framework. Five extensions were purchased from legitimate developers and turned malicious through later updates; 14 were created by the threat actor with clean functionality and later updated with malware. One purchased extension, 'Enable Right Click & Copy — Smart Unlock + OCR,' had ~70,000 Chrome users and ~10,000 Edge users when malicious functionality appeared, totaling ~80,000 potentially exposed users. After Chrome removed the listing, the Edge version remained active. On August 14, 2026, attackers pushed an Edge update with a new command-and-control domain. The malicious extension used its access to: strip Content Security Policy (CSP) headers from visited pages, maintain a persistent WebSocket connection to attacker C2 infrastructure, and execute remotely delivered modules. The payload included 16 modules: a multi-chain wallet drainer, Ledger and Trezor recovery-phrase phishing, credential and form theft, crypto exchange session harvesting, browser-history exfiltration, and a fake Chrome update instructing victims to run an attacker-supplied command. Microsoft Edge supports Chromium extension APIs, meaning the same extension code can run in both Edge and Chrome. Edge also allows installation of Chrome Web Store extensions, complicating enterprise oversight as two employees may run similar tools from different stores with different extension IDs, publishers, and update histories.

Mitigation steps

1. Use Socket's browser extension security platform to continuously monitor extensions across Chrome, Firefox, and Microsoft Edge Add-ons ecosystems. 2. Do not rely solely on one-time extension reviews at approval time; implement continuous analysis of every new version/update. 3. Track extension ownership changes, as extensions can be sold and turned malicious without user notification. 4. Monitor extensions across multiple stores (Chrome Web Store and Edge Add-ons) since removal from one store does not resolve risk in another. 5. Investigate extension permissions alongside actual code behavior, as permissions alone do not reveal malicious intent. 6. Use Microsoft Edge administrator policies to allow, block, or force-install extensions as a baseline control. 7. Alert on extensions that strip CSP headers, establish persistent WebSocket connections, or load remote code from external domains. 8. Correlate extensions through shared infrastructure, reused code, and publisher patterns to detect coordinated campaigns. 9. Enterprise customers should contact their Socket account team to enable Edge extension coverage.

Affected products

  • Enable Right Click & Copy — Smart Unlock + OCR (malicious extension)
  • Google Chrome (browser extensions via Chrome Web Store)
  • Ledger hardware wallet (targeted via phishing module)
  • Microsoft Edge (browser extensions via Microsoft Edge Add-ons store)
  • Trezor hardware wallet (targeted via phishing module)

IOC's

New command-and-control domain pushed via Edge extension update on August 14, 2026, Persistent WebSocket connection to attacker C2 infrastructure, CSP header stripping behavior in browser extension, Remote module loading from C2 server within extension, Extension: 'Enable Right Click & Copy — Smart Unlock + OCR' (Chrome and Edge versions), 16 remotely delivered malware modules including wallet drainer, credential theft, and session harvesting

Categories

  • Data Breach & Exfiltration
  • Ransomware & Malware
  • Supply Chain & Dependencies
  • Web Technologies