Researchers identified a campaign involving 19 malicious browser extensions distributed through the Google Chrome Web Store and Microsoft Edge Add-ons marketplace, with reported installations exceeding 2.3 million users. Fourteen extensions were published as apparently legitimate software, while five were acquired from their original developers and later updated with malicious functionality, leaving users unaware that ownership and code had changed.
The extensions contacted command-and-control infrastructure to retrieve replaceable modules, bypassed Content Security Policy controls, and injected code into targeted web pages. They could steal credentials, payment data, Facebook and LinkedIn information, browsing history, cryptocurrency assets, and hardware-wallet seed phrases; some also overlaid pages with ClickFix lures that impersonated browser-update notices and persuaded victims to run malicious commands, potentially extending compromise beyond the browser.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers identified 16 malicious modules that could steal web-form credentials and payment data, Facebook and LinkedIn data, browsing history, cryptocurrency assets, and hardware-wallet seed phrases. Other modules replaced page content with ClickFix prompts designed to persuade victims to run malicious commands outside the browser.
At the end of August, researchers reported finding 18 malicious Google Chrome extensions and one malicious Microsoft Edge extension. They assessed that the 19 extensions were likely part of one campaign because of similarities in their malicious code and techniques.
A Koi Security report stated that Google and Microsoft had trusted malicious extensions that were installed by 2.3 million users.
The operators added malicious functionality to the extensions through subsequent updates, including automatic Chrome updates. The extensions contacted command-and-control servers for changeable malicious modules and disabled Content Security Policy protections to inject code into victims' visited pages.
The operators created 14 extensions that initially offered their advertised legitimate functions and acquired five legitimate extensions from their developers, including their existing user bases. Users were not notified when ownership changed.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.