19 Chrome extensions were secretly stealing data. Uninstall these now
Security experts at Socket are warning about browser extensions for Google Chrome and Microsoft Edge that contain malware. The accompanying report mentions a total of 19 add-ons that were deliberately infected with malicious code in order to intercept user data and steal access details to digital wallets.
The affected extensions were available in the official Chrome and Edge web stores and actually performed useful functions. Only later, after significant adoption, were they retrofitted with malicious code.
About 14 of the 19 extensions were made by the attackers themselves. The remaining 5 were created by other developers, then later purchased by the attackers. Most of the extensions were designed for Google Chrome, with add-ons for the Edge browser added later.
Both Microsoft and Google have already removed the malicious browser add-ons from their respective web stores. However, anyone who has already installed them must still take action, as they aren’t automatically removed from affected browsers.
These are the names of the extensions that were infected with malware and should be uninstalled immediately:
- Enable Right Click & Copy – Smart Unlock + OCR
- RapidLens – Google Lens for Screen Search & Images
- QuickLens – Search Screen with Google Lens
- Password Protect PDF
- Allow Copy – Select & Enable Right-Click
- PixelCheck
- Creative Library – Ad Spy Tool
- Website Traffic Checker: MirrorSphere SEO Stats
- Site Signal – Website Traffic & SEO Checker
- SEO Pulse Pro – Website Traffic & SEO Analyser
- Private Crypto News Reader
- Blockfolio: Address Monitor
- Crypto Rates & Fiat Converter
- Crypto Alerter: Price Alerts & Volatility Warnings
- DeFi Pulse Tracker
- Crypto Price Badge: Quick Glance
- Multi-Chain Explorer
- LedgerLook: Wallet Checker
- Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray
The most widely used extension is apparently “Enable Right Click & Copy – Smart Unlock + OCR,” which had gained around 70,000 users before it was removed from the store. The malware contained within it, which was injected via a backdoor, was able to intercept browser history, login details, and crypto tokens without being detected.
According to Socket, the malware campaign responsible for these infections has been active for two years and has largely flown under the radar. As users of the affected browser extensions receive no notification that they’ve been removed from the store, the malware can continue to intercept data and cause damage. You should therefore take immediate action if you have used any of these in the past.
You should also check regularly whether all the add-ons you’ve installed are still working properly and are still officially supported by Chrome, Edge, and other browsers. It only takes a few clicks, but those few clicks could make all the difference.
Tip: Whether you keep your browser up to date, you need proper antivirus protections if you want your PC to remain secure and private. Check out our picks for the best antivirus software for Windows as well as best VPN services to stay ahead of security problems.