Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-29 ยท updated: 2026-08-29 ยท tags: [incident, browser-extension, supply-chain, credential-theft, crypto-wallet] ยท confidence: high ยท affected_sectors: [technology, finance] ยท au_impact: true

Socket Identifies 19 Chrome and Edge Extensions Delivering Malware

Security research firm Socket identified 19 browser extensions (18 for Chrome, one for Edge) carrying a modular malware framework that swipes crypto-wallet secrets and steals credentials. The extensions use an AES-GCM encrypted communication channel with a key derived from the extension ID and install UUID to evade detection, aiming to exfiltrate wallet recovery phrases.

Attribute Detail
Scope 19 extensions (18 Chrome, 1 Edge)
Capability Crypto-wallet secret swiping; credential theft
Evasion AES-GCM encrypted channel; key derived from extension ID + install UUID
Payload target Wallet recovery phrases
Source Socket (via The Hacker News) โ€” Tier 2/4

A browser-supply-chain gambit: seemingly innocuous extensions exfiltrate wallet recovery phrases that grant full control of crypto holdings โ€” relevant to AU/NZ consumers and enterprises running such extensions.

Same-day/related

Source