In a fresh development, this doesn't affect our editorial independence. When you purchase through links in our articles, we may earn a small commission.
As part of the ongoing story, the accompanying report mentions a total of 19 add-ons that were deliberately infected with malicious code in order to intercept user data and steal access details to digital wallets. Security experts at Socket are warning about browser extensions for Google Chrome and Microsoft Edge that contain malware.
The report highlights that only later, after significant adoption, were they retrofitted with malicious code. The affected extensions were available in the official Chrome and Edge web stores and actually performed useful functions.
In a fresh development, the remaining 5 were created by other developers, then later purchased by the attackers. Most of the extensions were designed for Google Chrome, with add-ons for the Edge browser added later. About 14 of the 19 extensions were made by the attackers themselves.
In a fresh development, however, anyone who has already installed them must still take action, as they aren’t automatically removed from affected browsers. Both Microsoft and Google have already removed the malicious browser add-ons from their respective web stores.
As part of the ongoing story, these are the names of the extensions that were infected with malware and should be uninstalled immediately:.
The report highlights that the malware contained within it, which was injected via a backdoor, was able to intercept browser history, login details, and crypto tokens without being detected. The most widely used extension is apparently “Enable Right Click & Copy – Smart Unlock + OCR,” which had gained around 70,000 users before it was removed from the store.
According to the latest update, as users of the affected browser extensions receive no notification that they’ve been removed from the store, the malware can continue to intercept data and cause damage. You should therefore take immediate action if you have used any of these in the past. According to Socket, the malware campaign responsible for these infections has been active for two years and has largely flown under the radar.
Industry observers note that it only takes a few clicks, but those few clicks could make all the difference. You should also check regularly whether all the add-ons you’ve installed are still working properly and are still officially supported by Chrome, Edge, and other browsers.
As part of the ongoing story, check out our picks for the best antivirus programs for Windows as well as best VPN services to stay ahead of security problems. Tip: Whether you keep your browser up to date, you need proper antivirus protections if you want your PC to remain secure and private.
In a fresh development, this article originally appeared on our sister publication PC-WELT and was translated and localized from German.
The report highlights that after studying communication science, she went straight into a job at PCMagazin and Connect Living. Since then, she has been writing about everything to do with PCs and technology topics, and has been a permanent editor at our German sister site PC-WELT since May 2024. Laura is an enthusiastic gamer as well as a movie and TV fan.