19 Malware-Infected Browser Extensions Discovered
Recent warnings from security experts at Socket concern 19 browser extensions for Google Chrome and Microsoft Edge that are infected with malware. These add-ons were designed to intercept user data and steal access to crypto wallets. The extensions were available in the official web stores of Chrome and Edge and provided useful functions before being later embedded with malicious code. Of the 19 affected extensions, 14 were programmed by the attackers themselves, while the remaining five were sourced from other developers and apparently acquired. Most of these add-ons were originally designed for Google Chrome before extensions for the Edge browser were also added.
The security researchers at Socket have identified the extensions and informed the respective companies. The extension with the most users, Enable Right Click & Copy – Smart Unlock + OCR, had about 70,000 users before its removal. This extension was able to inject malware through a backdoor that stealthily intercepted browsing histories, credentials, and crypto tokens. The malware campaign behind these attacks has been active for two years and has largely gone undetected. Microsoft and Google have since removed the harmful extensions from their stores.
However, users who have already installed these add-ons need to take action, as removal from the store does not automatically lead to uninstallation. Security researchers recommend regularly checking all installed add-ons and ensuring they are still supported by the browser providers. The list of affected extensions includes PixelCheck, Creative Library, Website Traffic Checker: MirrorSphere, and SEO Pulse Pro. These add-ons were developed to provide various useful functions but are now classified as security risks. Users should be particularly cautious, as the malware can continue to intercept data as long as the extensions are installed.
Socket recommends immediately uninstalling the affected extensions to minimize the risk of data loss. The security situation is deemed critical, as the malware is capable of stealing sensitive information without users noticing. Researchers emphasize the importance of taking the security of browser extensions seriously and regularly reviewing them. The affected extensions pose a danger not only to private users but can also harm businesses that rely on the security of their data. The attackers exploit vulnerabilities in the extensions to gain unauthorized access to sensitive information.
Users should be aware that even useful add-ons can present potential security risks. The security researchers at Socket have identified the malware campaign as one of the most extensive of its kind that has been active in recent years. The attackers have managed to keep their activities largely undetected, complicating the discovery and mitigation of the threat. Users are urged to remain vigilant and regularly check their browser extensions. The affected extensions exemplify the importance of verifying the origin and security of software before installation.
Security researchers advise using only extensions from trusted sources and regularly checking for updates. The threat of malware in browser extensions remains a serious issue affecting both private and business users. The security situation will continue to be monitored, and users should stay informed about new developments. Socket has announced that it will release further information about the malware campaign and its impact on users. The researchers are working to analyze the background of the attacks and develop possible countermeasures.
The affected extensions represent a serious security risk that should not be ignored. Users who have installed any of the mentioned extensions should uninstall them immediately to protect their data. The security researchers at Socket have published the list of affected extensions to help users act quickly. The complete list of affected extensions includes: Enable Right Click & Copy – Smart Unlock + OCR, RapidLens – Google Lens for Screen Search & Images, QuickLens – Search Screen with Google Lens, Password Protect PDF, Allow Copy – Select & Enable Right Click, PixelCheck, Creative Library – Ad Spy Tool, Website Traffic Checker: MirrorSphere, SEO Stats Site Signal – Website Traffic & SEO Checker, SEO Pulse Pro – Website Traffic & SEO Analyzer, Private Crypto News Reader, Blockfolio: Address Monitor, Crypto Rates & Fiat Converter, Crypto Alerter: Price Alarms & Volatility Warnings, DeFi Pulse Tracker, Crypto Price Badge: Quick Glance, Multi-Chain Explorer, LedgerLook: Wallet Checker, Meta & Facebook Ad Library Spy. The security researchers at Socket recommend uninstalling all affected extensions immediately to minimize the risk of data loss. Users should also stay informed about the latest security updates and regularly check their browsers for vulnerabilities.
The malware campaign behind these extensions is a serious issue that jeopardizes the security of user data. Socket has identified the threat as one of the most extensive of its kind that has been active in recent years. The security researchers at Socket have identified the affected extensions and informed the respective companies.
The complete list of affected extensions has been published to help users act quickly. The affected extensions represent a serious security risk that should not be ignored.
The affected extensions exemplify the importance of verifying the origin and security of software before installation.
💬 Comments (0)
No comments yet. Be the first to comment!