← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 27, 2026 · 16:01via Socket Security Blog

19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads

Brief

Socket identified 19 malicious extensions published in the last six months, delivering an extendable malware framework. Identified malware samples create WebSocket communication channel with command and control (C2) server, perform CSP stripping and abuse XSS injection to trigger execution of malicious payloads previously downloaded from the C2 server.

Malicious capabilities are primarily focused on, but not limited to, wallet secret stealing and crypto draining. The most impactful tactic is acquisition of established extensions offered for sale with an existing user base, which then get weaponized with malicious functionality.

The Socket Threat Research team identified 18 Chrome extensions and 1 Edge extension sharing similarities in malicious code and malware operation techniques.

Read more on Socket Security Blog