A set of browser extensions for Google Chrome and Microsoft Edge delivered a malware framework capable of stealing cryptocurrency, sensitive data and browser history, according to BleepingComputer, citing research from application security company Socket. The same framework could also inject ClickFix lures, the report says. Socket’s investigation found 16 malicious modules in the campaign. BleepingComputer reports that the modules served distinct purposes and were designed to be “highly extensible,” meaning the framework could be adapted with additional payloads over time. Socket warned that more modules may exist and that new payloads could be deployed as the malware evolves. The campaign may have been active since early 2024, according to Socket’s investigation as reported by BleepingComputer. A notable feature of the operation is that many of the extensions were not malicious when first published. Socket says they initially provided the functionality they advertised, then became dangerous later. That update path matters. BleepingComputer reports that five of the extensions were acquired from their original creators and then injected with malware through automatic updates. For users, that means an extension that looked legitimate at installation could have changed behavior later without a fresh manual install. One example cited in the report is “Enable Right Click & Copy — Smart Unlock + OCR,” which BleepingComputer says was the only extension in the campaign available for both Chrome and Edge. When it turned malicious, it had at least 70,000 Chrome users and 10,000 installs on Edge, according to the report. Google removed the extension from its marketplace early, BleepingComputer reports, but Socket said the Edge version remained available when Socket published its findings. The malware’s mechanics were browser-native. Once installed, BleepingComputer reports, it established an encrypted WebSocket connection to command-and-control servers, downloaded JavaScript modules, removed Content Security Policy headers from every website the user visited, and injected malicious scripts into pages through hidden HTML elements. Socket’s report also included the extension IDs and command-and-control domains it uncovered. By the time BleepingComputer published its report, none of the malicious extensions were available in the Chrome Web Store. The report advises users who had any of the extensions installed to assume their credentials may be compromised and change login passwords. It also says potentially affected cryptocurrency holders should move assets to a newly created wallet as soon as possible. Who benefits: Attackers benefit from the trust and distribution of established browser extensions, especially where acquisitions let them inherit existing user bases. Users benefit if browser stores and security teams identify and remove malicious updates quickly. Who's exposed: Chrome and Edge users who installed the affected extensions are exposed, particularly if they stored credentials in the browser or used cryptocurrency wallets while the extension was active. The report specifically flags impacted crypto holders as needing to move assets to a new wallet.