Malicious Chrome/Edge Extension Framework (Crypto & Data Stealer with ClickFix Lures)
First seen Aug 31, 2026 · Updated Aug 31, 2026
Multiple malicious extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons store delivered a modular malware framework capable of stealing cryptocurrency, browsing history, and other sensitive data. The campaign also deployed ClickFix-style social engineering lures to trick users into executing further malicious commands, expanding the attack's reach beyond simple browser compromise.
Technical Analysis
The malicious extensions functioned as loaders for a modular framework, downloading and executing additional payloads post-installation to evade static store review checks. Modules observed include browser history and session data exfiltration, cryptocurrency wallet targeting (likely via clipboard hijacking or wallet extension interaction), and ClickFix lures that social-engineer victims into pasting and executing attacker-supplied scripts (often PowerShell) under the guise of fixing a fake error. Because the extensions operate with broad browser permissions, they can access cookies, session tokens, and locally stored credentials, including API keys and OAuth tokens used by browser-based AI agent tools, RAG pipeline dashboards, and LLM API consoles, creating a credential-theft pathway into agent infrastructure for any organization where employees browse with these extensions installed on machines that also manage agent secrets.
Affected Systems
Google Chrome and Microsoft Edge browsers with the malicious extensions installed from the Chrome Web Store or Edge Add-ons store; any Windows/macOS/Linux endpoints where affected extensions were active
Indicators of Compromise
- Malicious Chrome Web Store extension listings (names/IDs not fully disclosed in source)
- ClickFix lure pages triggering clipboard-paste PowerShell execution
- C2 infrastructure used for module delivery and data exfiltration (not specified in source)
Remediation Steps
- 1
Audit installed browser extensions
Review all Chrome and Edge extensions across managed endpoints and remove any unrecognized or unverified extensions, particularly those with recent updates or broad permissions.
- 2
Revoke and rotate exposed credentials
Rotate browser-stored credentials, session tokens, and API keys (including those used for AI agent, LLM, or RAG service access) on any machine that had the affected extensions installed.
- 3
Block ClickFix-style execution
Educate users on ClickFix social engineering tactics and deploy endpoint controls to detect/block clipboard-paste-to-terminal or run-dialog execution patterns.
- 4
Enforce extension allowlisting
Use enterprise browser management policies to restrict extension installation to a vetted allowlist and disable installation from unmanaged sources.
- 5
Monitor for cryptocurrency and data theft indicators
Deploy monitoring for unusual clipboard modification, wallet address swapping, and unexpected outbound data transfers from browser processes.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.