Cybersecurity researchers at Socket uncovered a campaign involving 19 malicious browser extensions designed to steal cryptocurrency and account information. Eighteen extensions targeted Google Chrome and one targeted Microsoft Edge; Socket said they had been active or weaponized over the past six months, with the operation possibly dating back to February 2024. Fourteen extensions were created by the threat actor, while five were acquired from legitimate developers and later made malicious. The most dangerous identified extension, "Enable Right Click & Copy — Smart Unlock + OCR," had about 70,000 Chrome users when its malicious features were introduced and roughly 10,000 users on Edge. The extensions were distributed through official browser stores. The Chrome versions have since been removed from the Chrome Web Store, but the Edge version remained available, Socket said. The malware can remove Content Security Policy protections and includes a wallet drainer targeting EVM-compatible networks, Solana and Tron. It can alter wallet-connection and token-swap buttons, display fake Ledger and Trezor recovery or update pages to capture seed phrases, and harvest authenticated sessions and account data from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit and MetaMask. Other modules target Facebook and LinkedIn accounts, steal browsing history and deploy ClickFix-style fake browser-update pages. Users should audit installed extensions, remove suspicious software, scan affected devices and move crypto to a new wallet if compromise is suspected. Socket also recommends checking developers and reviews, using hardware wallets for substantial holdings, enabling two-factor authentication and keeping browsers and extensions updated.