:

CHROME EXTENSIONS DEPLOYED CRYPTO-STEALING MALWARE

INDUSTRY DESK2 MIN READ
SUN, AUG 30, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Multiple extensions in the Chrome Web Store and Microsoft Edge delivered malware that stole cryptocurrency, browser data, and user history while injecting fraudulent ClickFix lures.

Security researchers identified a coordinated malware campaign targeting Chrome and Edge users through seemingly legitimate extensions available in official app stores. The compromised extensions deployed a malware framework capable of multiple attack vectors. The malware performed several malicious functions: - Cryptocurrency theft: Targeted digital wallets and crypto-related accounts for credential harvesting - Data exfiltration: Harvested sensitive user information and browser history - Injection attacks: Deployed ClickFix lures—fake support messages designed to trick users into downloading additional malware The presence of these extensions on official platforms highlights a persistent challenge for app store moderation. While Google and Microsoft maintain submission review processes, determined attackers continue finding ways to circumvent security checks, either through obfuscated code or gradual payload deployment after initial approval. Users who downloaded affected extensions face multiple risks. The stolen data could enable identity theft, account takeovers, and financial fraud. Cryptocurrency holdings remain particularly vulnerable, as stolen wallet credentials provide direct access to digital assets. Recommended actions: Users should immediately audit installed extensions and remove any unfamiliar or suspicious tools. Review browser settings and saved passwords, particularly for financial and cryptocurrency accounts. Consider changing passwords for sensitive services, especially those with cryptocurrency access. For additional protection, use hardware wallets for significant crypto holdings rather than browser-based solutions. Enable two-factor authentication on all financial accounts. Monitor financial accounts and credit reports for fraudulent activity. Google and Microsoft have removed identified extensions from their stores. However, this incident reinforces the importance of reviewing extension permissions carefully before installation. Legitimate extensions typically request minimal permissions—tools requesting broad data access warrant scrutiny. Researchers recommend users visit official extension store pages only through legitimate channels and verify developer information before installation. The incident underscores ongoing risks in browser extension ecosystems despite platform-level security measures.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.

2H AGOAI Desk

A new survey reveals strong public opposition in the UK to government surveillance of encrypted communications. The findings highlight growing concern over privacy rights as lawmakers continue debating message scanning proposals.

2H AGOIndustry Desk

PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.

6H AGOSecurity Desk

A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.

9H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.