NewsHK
The pattern of browser extensions changing hands and turning malicious has reached another user base, this time pushing fake Chrome update warnings to tens of thousands of people. Socket researchers, publishing on Aug.
27, traced the campaign to Enable Right Click & Copy - Smart Unlock + OCR, an extension that was acquired by a threat actor and updated with malicious code after building a legitimate following.
Google delisted it from the Chrome Web Store on Aug. 14, and a spokesperson confirmed the company investigated and took action to protect users.
The extension started as a tool for restoring right-click and copy features on websites that block them. It changed hands at some point after that.
Keep reading