Updated
Updated · Fox News · Aug 31
Threat Actor Weaponizes 70,000-User Chrome Extension for Fake Update Scams
Updated
Updated · Fox News · Aug 31

Threat Actor Weaponizes 70,000-User Chrome Extension for Fake Update Scams

3 articles · Updated · Fox News · Aug 31

Summary

  • Socket researchers said the once-legitimate “Enable Right Click & Copy” extension was acquired and updated with malicious code that pushed fake Chrome “Critical Update” warnings to users.
  • Around 70,000 users had the extension when the malicious functionality appeared, and Google delisted it from the Chrome Web Store on Aug. 14 after flagging it as potentially malicious.
  • Socket’s Aug. 27 research tied the case to a broader campaign spanning 19 Chrome and Edge extensions, with capabilities including credential theft, crypto-wallet draining, phishing-page injection and fake browser-update lures.
  • Recent user reviews — despite a roughly 4.7-star average rating — said disabling or removing the extension stopped the pop-ups, underscoring how old ratings can mask newly weaponized software.
  • Google says Chrome normally updates through the browser itself, so webpages urging downloads such as .vbs scripts or unfamiliar .exe files are a key warning sign of browser-based malware or hijacking.

Insights

How did a highly rated Chrome extension silently transform into a crypto-draining weapon without triggering Google's security alarms?
If star ratings can no longer guarantee safety, what hidden dangers are lurking in the browser extensions you installed years ago?