Socket Finds Trusted Extensions Turned Malicious

Socket found 19 malicious Chrome and Edge extensions in the last six months, including 18 Chrome extensions and one Edge extension. The most striking case was an extension with about 70,000 Chrome users after it was acquired and later weaponized in an update. The malware opens a WebSocket channel to command and control, strips Content Security Policy controls, and uses cross-site scripting injection to trigger payloads it first pulls down from the attacker. That lets the extension steal wallet secrets, drain crypto, and pull credentials while looking like a normal update to software people already trusted. The exposure sits in the update path, not just the install path: if your fleet allows extensions that can touch sessions, wallets, or logins, a once-legitimate add-on can become a distribution channel for theft after it has already earned trust.

Part of the PlainSec briefing for 2026-08-27

Every edition of this story: Socket Finds Trusted Extensions Turned Malicious

Sources