type: incident ยท created: 2026-08-29 ยท updated: 2026-08-29 ยท tags: [incident, browser-extension, supply-chain, credential-theft, crypto-wallet] ยท confidence: high ยท affected_sectors: [technology, finance] ยท au_impact: true
Socket Identifies 19 Chrome and Edge Extensions Delivering Malware
Security research firm Socket identified 19 browser extensions (18 for Chrome, one for Edge) carrying a modular malware framework that swipes crypto-wallet secrets and steals credentials. The extensions use an AES-GCM encrypted communication channel with a key derived from the extension ID and install UUID to evade detection, aiming to exfiltrate wallet recovery phrases.
| Attribute | Detail |
|---|---|
| Scope | 19 extensions (18 Chrome, 1 Edge) |
| Capability | Crypto-wallet secret swiping; credential theft |
| Evasion | AES-GCM encrypted channel; key derived from extension ID + install UUID |
| Payload target | Wallet recovery phrases |
| Source | Socket (via The Hacker News) โ Tier 2/4 |
A browser-supply-chain gambit: seemingly innocuous extensions exfiltrate wallet recovery phrases that grant full control of crypto holdings โ relevant to AU/NZ consumers and enterprises running such extensions.
Same-day/related
- This echoes the earlier 737 Chrome Vpn Extensions Caught Routing Traffic Through Single Proxy Infrastruc browser-extension supply-chain finding.