
One such extension, “Enable Right Click & Copy — Smart Unlock + OCR”, is available for Chrome and Edge. When the program became malicious, its user base in Chrome numbered more than 70,000 people, and in Edge—about 10,000, according to estimates by Socket, as reported by bits.media.
Once it appears in the browser, the malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from every visited site, and injects malicious scripts via hidden HTML elements. This allows hackers to intercept user data on crypto exchange websites and other services.
Socket researchers discovered that the malicious modules can drain EVM wallets, Solana, and Tron by spoofing the “Connect Wallet” and “Exchange” buttons, as well as replacing the websites of Ledger and Trezor hardware wallets with phishing pages to steal seed phrases. The malicious modules also steal crypto assets and account data from major crypto exchanges—including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, and Bybit—as well as from the MetaMask crypto wallet.
In addition, the extensions transmit to hackers the data and passwords entered on all websites, collect information from Facebook and LinkedIn accounts, and extract browsing history. The malware also displays fake browser updates, prompting victims to carry out commands desired by the attackers. None of the malicious extensions are currently available in the Chrome Web Store, but Edge users are advised to check their installed extensions.
Malwarebytes Labs recently warned of a new phishing scheme—hackers are creating fake websites that purport to verify crypto addresses for money laundering and violations of international sanctions (AML). To gain unauthorized access to computers, hackers also exploited a vulnerability in the “Screen Sharing” feature of Apple’s macOS operating system.





















