# Researchers trace malicious Chrome and Edge extensions to credential and crypto theft

_Sunday, August 30, 2026 at 10:17 AM EDT · Security · Latest · Tier 2 — Notable_

![Researchers trace malicious Chrome and Edge extensions to credential and crypto theft — Primary](https://www.bleepstatic.com/content/hl-images/2023/11/28/Google_Chrome.jpg)

Researchers at Socket identified a malware framework distributed through Chrome and Edge extensions, including five extensions acquired from original creators and later altered through automatic updates. The framework opened encrypted WebSocket links to command-and-control servers, fetched JavaScript modules, stripped content-security-policy headers and injected scripts. Socket observed modules targeting crypto wallets, exchange sessions, credentials and browsing data. Google removed the cross-browser example from its store, but its Edge version remained available at the time of Socket's report.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/)

---
Canonical: https://techandbusiness.org/newswire/pwubNixjq7VsVl9XBK99QE
Retrieved: 2026-08-30T17:14:27.372Z
Publisher: Tech & Business (techandbusiness.org)
