Skip to content
  • NVDA
  • AAPL
  • MSFT
  • AMD
  • TSLA

Chrome Web Store extensions caught stealing crypto, browser data

Extensions for Chrome and Edge delivered a malware framework that stole crypto, data, and browser history.

By TMRO Staff·2 min read
Chrome Web Store extensions caught stealing crypto, browser data
BleepingComputer

Key points

  • Extensions on Chrome Web Store and Microsoft Edge delivered malware framework.
  • Malware stole cryptocurrency, sensitive data, and browser history.
  • Extensions also injected ClickFix lures.
  • Reported by BleepingComputer on 2026-08-30.
  • Affects both Google Chrome and Microsoft Edge users.

Multiple extensions for Google Chrome and Microsoft Edge have been caught delivering a malware framework that steals cryptocurrency, sensitive data, and browser history, according to a report published on 2026-08-30 by BleepingComputer. The extensions also injected ClickFix lures, a social engineering technique that tricks users into executing malicious code.

The report did not name the specific extensions or provide a count, but it said the malware framework deployed modules to perform the theft. The extensions were available on the Chrome Web Store, which also serves Microsoft Edge, as Edge can install Chrome extensions.

Malware framework with multiple modules

The malware framework was designed to be modular, with separate components for stealing cryptocurrency, sensitive data, and browser history. It also included a module to inject ClickFix lures, which typically display fake error messages or prompts that urge users to copy and run a command, leading to infection.

BleepingComputer's report did not detail how the extensions were distributed or how many users were affected. It also did not specify whether the extensions have been removed from the stores.

Impact on Chrome and Edge users

Because the extensions were available on the Chrome Web Store, they could be installed by both Google Chrome and Microsoft Edge users. The report did not indicate whether the extensions were also available on other Chromium-based browsers.

The theft of browser history and sensitive data could expose users to further attacks, such as credential stuffing or identity theft. The cryptocurrency theft suggests the attackers targeted users with digital wallets.

What happens next

The report leaves open the question of whether the extensions have been taken down and whether Google or Microsoft have issued any warnings. Users who have installed extensions from the Chrome Web Store are advised to review their installed extensions and remove any that are suspicious. The full scope of the campaign, including the number of affected users and the identities of the extensions, remains unknown.

Why it matters

The discovery highlights a persistent threat vector: legitimate-looking browser extensions can serve as distribution channels for sophisticated malware. Because extensions run with high privileges in the browser, they can access sensitive data and inject content into web pages, making them a potent tool for credential theft and financial fraud. Users and organizations relying on browser extensions should review their installed extensions and consider the risks.

The data

Market data

NASDAQ:MSFT
513.53 USD+8.47 (1.68%)
NASDAQ:GOOGL
346.59 USD+5.94 (1.74%)

finnhub ·

TMRO coverage, last 90 days

Alphabet
18 storieslast on 30 Aug 2026
Microsoft
4 storieslast on 28 Aug 2026

TMRO Report archive ·

Sources

TMRO Report writes original coverage based on the material listed above.