Hijacked browser extension spread fake Chrome update warnings to 70,000 users, Socket researchers find
The pattern of browser extensions changing hands and turning malicious has reached another user base, this time pushing fake Chrome update warnings to tens of thousands of people. Socket researchers, publishing on Aug. 27, traced…
Key takeaways
- Socket researchers reported on Aug. 27 that a hijacked Chrome extension, Enable Right Click & Copy - Smart Unlock + OCR, was pushing fake Chrome update warnings after being acquired by a threat actor and updated with malicious code.
- The extension had approximately 70,000 users when the malicious version appeared, though not every user necessarily received the compromised build.
- Google delisted the extension from the Chrome Web Store on Aug. 14 and confirmed it investigated and took action to protect users.
- Socket linked the extension to a wider campaign involving 19 Chrome and Edge extensions capable of credential theft, cryptocurrency wallet draining, injected phishing pages and fake browser update lures.
- Users of Chromium-based browsers including Brave and Opera reported the same fake Chrome update prompts, extending the campaign's reach beyond Chrome.
The pattern of browser extensions changing hands and turning malicious has reached another user base, this time pushing fake Chrome update warnings to tens of thousands of people. Socket researchers, publishing on Aug. 27, traced the campaign to Enable Right Click & Copy - Smart Unlock + OCR, an extension that was acquired by a threat actor and updated with malicious code after building a legitimate following. Google delisted it from the Chrome Web Store on Aug. 14, and a spokesperson confirmed the company investigated and took action to protect users.
The extension started as a tool for restoring right-click and copy features on websites that block them. It changed hands at some point after that. When the malicious version appeared, the extension had approximately 70,000 users, though Socket researchers caution that does not mean every user received the compromised build.
Nineteen extensions, one campaign
Socket's Aug. 27 findings placed this incident inside a wider operation. Researchers linked the extension to a campaign involving 19 Chrome and Edge extensions, with capabilities that included credential theft, cryptocurrency wallet draining, injected phishing pages and fake browser update lures. Several of those 19 also began as legitimate products before being acquired and turned against their users, Socket says.
Earlier this year, QuickLens - Search Screen with Google Lens changed ownership and received a malicious update after earning a Featured badge from Google. Researchers found it capable of injecting code and targeting sensitive information before Google removed it. A separate previously disclosed campaign had already traced the same arc across 4.3 million users.
Users of Chromium-based browsers including Brave and Opera have reported the same fake Chrome update prompts. Those browsers support many of the same extension types, so a campaign built around Chrome-branded warnings can reach well beyond Chrome's own user base.
What the star rating hid
Enable Right Click & Copy still averaged near 4.7 stars as August reviews filled with warnings about injected update alerts. Thousands of earlier positive ratings remain part of the overall score; more recent reviewers flagged the malicious behavior only after the update arrived. Several noted that disabling or removing the extension stopped the prompts.
Google's own guidance is direct: Chrome handles its updates automatically in the background. A webpage requesting a .vbs script or an unfamiliar .exe file as a browser update is not legitimate. Users can verify their version at Chrome > Help > About Google Chrome. Socket has 19 extensions in the broader campaign still to account for.
Related reading
Source · 來源