Chrome Web Store extensions caught stealing crypto, browser data
Multiple Chrome and Edge extensions delivered malware framework to steal crypto, data, and inject malicious scripts. Google removed the extension from its marketplace.
Intelligence analysis by Qwen 2.5 (3B)

Malicious Chrome and Edge extensions found in the Web Store that stole crypto, data, and injected malware. Google removed the extension, but Edge version remained available.
Bad guys put in some sneaky software in web browser add-ons that could steal your money and personal info. Google found out and took it off their store, but some people still have it.
Analysis
{"subheading":"The Malware Framework","content":["Researchers discovered a malware framework embedded in 19 extensions for Google Chrome and Microsoft Edge.","The framework was designed to be highly extensible and could be used to steal cryptocurrency, sensitive data, and browser history.","One example, the 'Enable Right Click & Copy — Smart Unlock + OCR' extension, was found to have a user base of over 70,000 on Chrome and 10,000 on Edge."]}
Key points
- 19 extensions found with malicious software in Chrome and Edge
- Google removed the extension from its marketplace
- Edge version remained available after removal
As security measures improve, fewer extensions will be found with malicious software.
Even with better security, some people might still have these bad extensions installed, risking their data.



