Malicious Chrome Web Store extensions caught stealing user data

By September 1, 2026, multiple extensions available in the official Chrome Web Store and Microsoft Edge extension stores were discovered delivering a malware framework that stole cryptocurrency, browser history, sensitive user data, and injected malicious advertising. The discovery raised questions about the effectiveness of app store security reviews.

5 reports · 4 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🤖 Malicious Google Chrome and Microsoft Edge extensions distributed via the official Web Store delivered a malware framework that steals cryptocurrency, sensitive data and browser history, and inject

mastodon:infosec-exchangeother29d ago kagi ↗

🤖 Malicious Google Chrome and Microsoft Edge extensions distributed via the official Web Store delivered a malware framework that steals cryptocurrency, sensitive data and browser history, and injects ClickFix lures. 🔗 https://www. bleepingcomputer.com/news/secu rity/chrome-web-store-extensions-caught-stealing-crypto-browser-data/ # Malware # CyberSec # InfoSec