Technology
Fake Chrome update scam linked to compromised extension network
Security researchers uncovered a campaign using 19 browser extensions to deliver malicious payloads and fake updates.
The short version
- A Chrome extension with around 70,000 users was acquired by a threat actor and modified to display fake browser update alerts and deliver malware.
- Google delisted the extension on August 14, and researchers at Socket linked it to a broader network of 19 extensions capable of credential theft and cryptocurrency wallet draining.
- Users are advised to inspect installed browser extensions, remove unrecognized add-ons, and check Chrome updates directly through internal browser settings.
Key facts
- The Chrome extension 'Enable Right Click & Copy - Smart Unlock + OCR', which had approximately 70,000 users and a 4.7-star rating, was acquired by a threat actor and updated with malicious functionality.[Fox News]
- Google delisted the extension from the Chrome Web Store on August 14 after investigating and flagging it as potentially malicious.[Fox News]
- Research published by cybersecurity firm Socket on August 27 connected the extension to a broader campaign involving 19 Chrome and Edge extensions.[Fox News]
- The identified extension campaign was capable of credential theft, cryptocurrency wallet draining, injected phishing pages, and fake browser update prompts.[Fox News]
What remains uncertain
- Security researchers noted that having the extension installed did not guarantee every user received the malicious version.[Fox News]