Affected Systems

Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024. Extensions delivered modular malware framework via updates after legitimate versions were acquired or compromised.

Exploitation Status

Active exploitation confirmed. All 19 extensions deployed in the wild, with at least five legitimate extensions acquired and weaponized via malicious updates. Google removed extensions from Chrome Web Store; some remained available on Edge add-ons store at time of disclosure (August 30, 2026).

Business Impact

Users with installed extensions face credential theft across all websites, cryptocurrency wallet draining (EVM, Solana, Tron), session hijacking on major exchanges (Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit), and ClickFix social engineering attacks. Malware uses encrypted WebSocket C2, removes CSP headers, and injects scripts into all visited sites. Framework is modular and extensible—additional payloads expected. Organizations must audit browser extensions, force password resets for affected users, and monitor for lateral movement from compromised credentials.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately audit all Chrome and Edge browser extensions against Socket's published list of 19 malicious extension IDs; uninstall any matches and quarantine affected endpoints
  • Force password resets for users who had malicious extensions installed, prioritizing cryptocurrency exchange accounts, financial services, and corporate SSO credentials
  • Review authentication logs and SIEM for anomalous logins from affected user accounts since early 2024; investigate any suspicious access patterns or privilege escalation
  • Block C2 domains published in Socket's report at perimeter firewalls and DNS filtering; monitor for WebSocket connections to unknown external hosts from browser processes
  • Implement browser extension allowlisting via Group Policy (Chrome) or Intune (Edge) to prevent installation of unapproved extensions; educate users on risks of third-party extensions