Skip to main content
Back to Newswire
Security

Researchers trace malicious Chrome and Edge extensions to credential and crypto theft

Researchers trace malicious Chrome and Edge extensions to credential and crypto theft Image: Primary
Researchers at Socket identified a malware framework distributed through Chrome and Edge extensions, including five extensions acquired from original creators and later altered through automatic updates. The framework opened encrypted WebSocket links to command-and-control servers, fetched JavaScript modules, stripped content-security-policy headers and injected scripts. Socket observed modules targeting crypto wallets, exchange sessions, credentials and browsing data. Google removed the cross-browser example from its store, but its Edge version remained available at the time of Socket's report.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire