{
  "id": 5141298,
  "title": "Popular Chrome extensions were quietly weaponized to steal crypto from 80,000 users",
  "url": "https://urgent.news/2026/09/02/popular-chrome-extensions-were-quietly-weaponized-to-steal-crypto",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-09-02T17:48:00.000Z",
  "source": {
    "name": "TechSpot",
    "slug": "techspot",
    "url": "https://www.techspot.com/news/113708-cyber-criminals-abused-popular-chrome-edge-extensions-steal.html"
  },
  "original_language": "en",
  "account": "Security researchers have recently uncovered a long-standing malicious campaign that exploited Chrome's extension system to steal cryptocurrency from an estimated 80,000 users. The cybercriminal group utilized 19 malicious extensions targeting Chrome and Edge browser users, with one extension gaining significant popularity on both platforms. The attackers primarily targeted Google's browser, but the campaign's determination to continue despite the removal of the extensions from the browsers' stores indicates one cunning mind behind the operation.\n\nOut of the 19 malicious add-ons, 14 were created by the cybercriminals themselves while five others were purchased from legitimate developers and companies. Initially, these add-ons functioned as advertised, but over the past six months, the hackers updated them with malicious code designed to compromise systems and extract users' data. Among these add-ons was a particularly popular extension called \"Enable Right Click & Copy - Smart Unlock + OCR,\" installed on 70,000 Chrome browsers and 10,000 Edge browsers, exposing a total of 80,000 users to the malicious software.\n\nThe investigators discovered that the attackers employed certain code-based attack patterns first identified in February 2024, managing the crypto-stealing campaign remotely through a flexible command-and-control domain infrastructure. The malicious extensions were ultimately removed from the Chrome and Edge stores, but users may still be part of the C2 infrastructure if they haven't manually removed all 19 listed add-ons. Despite Google's 2018 attempt to enhance security with the Manifest V3 API, the cybercriminals are likely to persist in targeting popular browser extensions even after the removal of Manifest V2.",
  "summary": "Socket Inc. researchers have identified 19 malicious extensions targeting Chrome and Edge users. The cybercriminal campaign primarily targeted Google's browser, but one extension gained significant popularity on both Chrome and Edge. In any case, the analysts believe a single \"mind\" is behind the campaign – and it's determined to keep... Read Entire Article",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}