Crypto加密GOOGL

Hijacked browser extension spread fake Chrome update warnings to 70,000 users, Socket researchers find

The pattern of browser extensions changing hands and turning malicious has reached another user base, this time pushing fake Chrome update warnings to tens of thousands of people. Socket researchers, publishing on Aug. 27, traced…

By Selene Vasquez·August 31, 2026·二〇二六年八月三十一日·2 min read

Key takeaways

  • Socket researchers reported on Aug. 27 that a hijacked Chrome extension, Enable Right Click & Copy - Smart Unlock + OCR, was pushing fake Chrome update warnings after being acquired by a threat actor and updated with malicious code.
  • The extension had approximately 70,000 users when the malicious version appeared, though not every user necessarily received the compromised build.
  • Google delisted the extension from the Chrome Web Store on Aug. 14 and confirmed it investigated and took action to protect users.
  • Socket linked the extension to a wider campaign involving 19 Chrome and Edge extensions capable of credential theft, cryptocurrency wallet draining, injected phishing pages and fake browser update lures.
  • Users of Chromium-based browsers including Brave and Opera reported the same fake Chrome update prompts, extending the campaign's reach beyond Chrome.

The pattern of browser extensions changing hands and turning malicious has reached another user base, this time pushing fake Chrome update warnings to tens of thousands of people. Socket researchers, publishing on Aug. 27, traced the campaign to Enable Right Click & Copy - Smart Unlock + OCR, an extension that was acquired by a threat actor and updated with malicious code after building a legitimate following. Google delisted it from the Chrome Web Store on Aug. 14, and a spokesperson confirmed the company investigated and took action to protect users.

The extension started as a tool for restoring right-click and copy features on websites that block them. It changed hands at some point after that. When the malicious version appeared, the extension had approximately 70,000 users, though Socket researchers caution that does not mean every user received the compromised build.

Nineteen extensions, one campaign

Socket's Aug. 27 findings placed this incident inside a wider operation. Researchers linked the extension to a campaign involving 19 Chrome and Edge extensions, with capabilities that included credential theft, cryptocurrency wallet draining, injected phishing pages and fake browser update lures. Several of those 19 also began as legitimate products before being acquired and turned against their users, Socket says.

Earlier this year, QuickLens - Search Screen with Google Lens changed ownership and received a malicious update after earning a Featured badge from Google. Researchers found it capable of injecting code and targeting sensitive information before Google removed it. A separate previously disclosed campaign had already traced the same arc across 4.3 million users.

Users of Chromium-based browsers including Brave and Opera have reported the same fake Chrome update prompts. Those browsers support many of the same extension types, so a campaign built around Chrome-branded warnings can reach well beyond Chrome's own user base.

What the star rating hid

Enable Right Click & Copy still averaged near 4.7 stars as August reviews filled with warnings about injected update alerts. Thousands of earlier positive ratings remain part of the overall score; more recent reviewers flagged the malicious behavior only after the update arrived. Several noted that disabling or removing the extension stopped the prompts.

Google's own guidance is direct: Chrome handles its updates automatically in the background. A webpage requesting a .vbs script or an unfamiliar .exe file as a browser update is not legitimate. Users can verify their version at Chrome > Help > About Google Chrome. Socket has 19 extensions in the broader campaign still to account for.

Related reading

Source · 來源

foxnews.com

Share · 分享

Frequently asked

What was the malicious extension and what did it originally do?

It was Enable Right Click & Copy - Smart Unlock + OCR, which started as a legitimate tool for restoring right-click and copy features on websites that block them before being acquired and updated with malicious code.

How can users tell a Chrome update warning is fake?

Chrome handles its updates automatically in the background, so a webpage requesting a .vbs script or an unfamiliar .exe file as a browser update is not legitimate. Users can verify their version at Chrome > Help > About Google Chrome.

Why did the extension still have a high star rating despite being malicious?

It averaged near 4.7 stars because thousands of earlier positive ratings remained part of the overall score, while more recent reviewers only flagged the malicious behavior after the update arrived.

Did every one of the 70,000 users receive the compromised version?

No; Socket researchers caution that the roughly 70,000 user count does not mean every user received the compromised build.

What stopped the malicious update prompts?

Several reviewers noted that disabling or removing the extension stopped the injected update prompts.