Browser extension malware spreading through trusted Chrome and Edge add-ons after automatic updates, exposing passwords, sessions, account data, and online activity.

Trusted Browser Extensions: How Legitimate Add-ons Become Malware

Category: Cybersecurity

Browser extensions are easy to forget about once they are installed. You add one to block ads, save passwords, capture screenshots, or fix some small annoyance, and then it quietly lives in your browser for months or years. The problem is that an extension you carefully checked in the past may not stay the same forever. A recent malware campaign shows how trusted Chrome and Edge extensions can change hands, receive malicious updates, and put existing users at risk without asking them to knowingly install anything new.

An Extension Can Change Over Time

Most people think about browser extension security before clicking the Install button. They check the developer, skim the reviews, look at how many people use the extension, approve its permissions, and assume the decision is finished. That is still a smart way to start. The problem is that those checks only tell you whether the extension appears trustworthy at that particular moment. Software keeps changing after it lands in your browser.

Research published by Socket on August 27, 2026, shows why that matters. The company identified 18 malicious Chrome extensions and one Microsoft Edge extension connected to an extensible malware framework. Researchers documented capabilities involving stolen credentials, cryptocurrency accounts, authenticated browser sessions, browsing history, altered webpages, and fake browser-update prompts.

What made the campaign especially concerning was the way some of those extensions reached users. According to Socket’s research into the malicious browser extensions, five had been purchased from legitimate developers before malicious functionality was added. The other extensions identified in the campaign had reportedly been created by the threat actor, released first with clean functionality, allowed to build trust, and then changed through later updates.

There is nothing automatically suspicious about a developer selling an extension. People lose interest in projects, change jobs, retire products, or simply decide that maintaining them is no longer worth the effort. The danger begins when an established extension, along with its reputation, permissions, name, and existing audience, ends up under the control of someone with malicious intentions.

Socket also pointed out another problem that most users would have little reason to think about: people are not necessarily notified when an extension changes ownership. The icon can look the same. The name can stay familiar. Yet the person deciding what code gets published next may be completely different.

Automatic Updates Extend Your Trust

Automatic updates are not the problem. In fact, they are an important part of keeping software secure because developers can patch vulnerabilities, fix bugs, improve compatibility, and get those improvements onto users’ computers without requiring everyone to update programs manually.

Chrome works that way with extensions. Google’s documentation covering the Chrome extension update lifecycle explains that Chrome checks for extension updates when the browser starts and periodically every few hours. For legitimate software, that is useful. Important fixes can reach users quickly with little effort on their part.

The catch is that an automatic update also carries your original trust forward.

Imagine installing a useful extension from a respected developer in 2024. You check its permissions, read reviews, use it for two years, and never notice anything suspicious. In 2026, the developer sells the extension. The new owner then publishes an update containing malicious code.

From your side, very little may appear to have changed. You did not search for questionable software, visit a strange download site, or click through an obvious warning. The extension that was already sitting in your browser simply received another version.

That is what makes this threat different from many familiar malware stories. Installing an extension is not only a decision about the software you see today. In practice, you are also putting some trust in whatever future versions arrive under that same extension identity.

One Extension Put 80,000 at Risk

One extension identified during the campaign shows why an existing user base can be so valuable to an attacker. The Chrome extension “Enable Right Click & Copy – Smart Unlock + OCR” had originally been developed by a legitimate organization before it was acquired.

Socket reported that the Chrome version had around 70,000 users when malicious functionality was introduced. A related Microsoft Edge version carrying the same malware had roughly another 10,000 users. Together, the two versions represented a potential exposure surface of about 80,000 people.

That does not mean researchers confirmed 80,000 infections. Socket specifically cautioned that the user count did not prove every person had received or executed the malicious version. That distinction matters. Still, the size of the audience shows why taking over an established extension can be attractive to an attacker.

Starting a brand-new malicious extension means beginning with nothing. There are no users, no track record, no years of positive reviews, and no familiar product name. Taking control of something people already use changes that equation completely.

BleepingComputer’s report on the extension malware campaign likewise reported that five extensions had been acquired from their original developers and later injected with malware through automatically delivered updates. Researchers found capabilities that went far beyond unwanted ads or browser redirects, including modules designed to capture credentials and form data, steal authentication information, collect browser history, target cryptocurrency services, and show fake software-update messages.

That is a lot of potential power for something many users barely notice sitting beside the address bar.

Browser Permissions Raise the Risk

Extensions need permissions to do their jobs. A password manager has to recognize login forms. A screenshot tool may need access to webpage content. An ad blocker needs to inspect resources being loaded by websites. None of those permissions automatically makes an extension dangerous.

The better question is whether the amount of access makes sense for what the extension is supposed to do. It is also worth asking what that access could mean if the extension were later compromised or placed under someone else’s control.

Google’s documentation on Chrome extension permissions shows how broad that access can become. Depending on the permissions an extension requests, it may be able to interact with browser APIs, websites, tabs, cookies, scripts, and other parts of the browsing experience.

Socket’s researchers found malware modules in this campaign capable of actions such as:

  • Capturing passwords, usernames, email addresses, and information typed into online forms.
  • Stealing authentication tokens, sessions, account details, and cryptocurrency information.
  • Collecting browser-history data and changing content shown on webpages.
  • Interfering with cryptocurrency websites and wallet activity.
  • Displaying fake browser-update prompts that could push victims toward additional malicious actions.

The point is not to become suspicious of every permission request you see. Instead, look for a reasonable match between the extension’s purpose and the access it wants. A simple utility that changes one small feature on a webpage deserves more scrutiny if it also asks for sweeping access across everything you browse.

The wider the access, the bigger the potential consequences when trust goes wrong.

Official Stores Cannot Promise Forever

Downloading extensions from the Chrome Web Store or Microsoft Edge Add-ons is still a better choice than getting browser software from an unknown download site. Official stores use policies, review processes, automated checks, and enforcement systems designed to catch malicious or abusive extensions.

Those protections reduce risk. They cannot promise that every extension will remain trustworthy forever.

Google explains that the Chrome Web Store review process is intended to protect users from malware, scams, data harvesting, and other policy violations. Existing extensions can also face additional review when needed.

The challenge is that extensions do not remain frozen in time. Code changes. Servers and other infrastructure can move. Features get added. Permissions may change. A developer can sell the project entirely. The people deciding what happens to the extension several years later might not be the same people who originally earned its reputation.

Reviews have the same limitation. A five-star review written in 2024 may be completely accurate about the extension that existed in 2024. It says very little about code published yesterday. Old blog posts, Reddit discussions, forum recommendations, and YouTube videos can age in exactly the same way. Someone may have thoroughly tested a product before recommending it, only for that product to change years later.

Popularity still has value when you are evaluating software. It just cannot prove permanent trustworthiness.

Small Businesses Have More at Stake

For a home user, a malicious browser extension might expose personal email, browsing data, financial accounts, or active online sessions. In a small business, that same extension could be running inside a browser connected to a much larger collection of important systems.

Think about what a typical employee opens during an ordinary workday. Company email, accounting software, cloud storage, customer databases, payment services, HR systems, social-media accounts, administrative dashboards, and vendor portals may all be running in separate tabs. An extension with broad access can potentially operate in the middle of that environment.

The risk grows quickly when every employee installs whatever seems useful. A ten-person business could end up with dozens of PDF tools, screenshot extensions, AI assistants, coupon add-ons, grammar tools, productivity products, and browser customizations spread across its computers. After a while, nobody may have a complete picture of what is installed or why.

Google recommends reviewing extensions and their permissions as part of managing Chrome extensions in an organization. Small businesses do not need an enterprise-sized IT department to follow the same basic idea.

A sensible extension policy can include:

  • Keep a short list of extensions approved for work computers.
  • Remove tools that no longer serve a real business purpose.
  • Check requested permissions before approving a new extension.
  • Reevaluate existing extensions from time to time.
  • Limit unnecessary employee installations when centralized management is available.
  • Investigate unexpected changes in a developer, name, permissions, features, or behavior.

The important idea behind the list is simple. “Approved” should mean that an extension appears acceptable based on what the business knows today. It should not mean trusted forever.

What You Should Check Today

You do not need advanced cybersecurity tools to perform a useful browser extension audit. Spending a few minutes looking at what is already installed may uncover extensions you forgot about years ago.

In Chrome, type chrome://extensions into the address bar. Edge users can enter edge://extensions. Do not just scan the icons and close the page. Go through the extensions one at a time and ask whether each still has a reason to be there.

If you have not used one in months and cannot think of a reason to keep it, removing it is usually the simplest choice. Every extension you delete is one less third-party program receiving future updates and potentially accessing some part of your browser.

Google’s Chrome extension management instructions also explain how users can review and change site access. Depending on the extension, you may be able to let it work only when clicked, only on selected websites, or across all sites. That difference matters when an extension has no good reason to access everything you browse.

For extensions you decide to keep, focus on a few practical checks:

  • Remove extensions you no longer use or recognize.
  • Review site permissions and reduce access that is not needed.
  • Look into unexpected changes in names, icons, developers, or features.
  • Avoid keeping several extensions that perform essentially the same job.
  • Continue updating Chrome, Edge, and legitimate extensions.
  • Pay closer attention to extensions that can read or change data across many websites.

If you used one of the extensions identified in this specific campaign, simply removing it may not be enough. BleepingComputer reported that potentially affected users should assume credentials could have been exposed and change relevant passwords. Because researchers also found capabilities involving authenticated sessions and cryptocurrency services, users with possible exposure should review important accounts, sign out active sessions where possible, and watch for activity they do not recognize.

Less Software Can Mean Less Risk

This incident also connects with a broader idea that fits the design approach behind JENI® Systems: software should have a clear reason to be on a computer, and it should not require more access or persistence than the job actually calls for.

JENI® is not a browser extension security product. It is not designed to detect malicious extensions, decide whether a browser add-on is trustworthy, or remove extension-based malware. Browser extensions still need to be reviewed through Chrome, Edge, or the management tools available to a business.

The privacy-first, on-demand approach behind JENI® does share one useful principle with this issue, though. Unnecessary software creates unnecessary exposure. A program should not remain installed forever simply because nobody has thought about it lately.

That idea fits browser extensions particularly well. Fewer unnecessary extensions mean fewer developers to trust, fewer update channels delivering new code, fewer permission sets to monitor, and fewer third-party components sitting inside the browser where so much personal and business activity takes place.

Supply Chain Attacks Use Old Trust

This campaign is also a useful example of software supply-chain risk. The phrase may sound technical, but the basic idea is straightforward: instead of convincing you to trust something obviously suspicious, an attacker goes after something you already trust.

Traditional security advice still matters. Avoid strange downloads. Be careful with unexpected attachments. Check developers before installing programs. Get software from reputable sources. Those steps prevent plenty of problems, but supply-chain attacks come at users from a different direction.

An attacker might target a software vendor, developer account, update channel, package, or established product that already has a good reputation. If that trusted path is compromised, malicious code can reach people who did nothing that would normally look reckless.

The National Institute of Standards and Technology discusses this larger issue in its work on cybersecurity supply chain risk management. NIST’s July 2026 due-diligence guidance focuses on researching suppliers and products so organizations can make informed decisions about both new acquisitions and systems they already use.

Browser extensions make the concept easy to understand. You can inspect an extension carefully today and make a perfectly reasonable decision to install it. Two years later, its code, developer, infrastructure, permissions, or ownership could look very different.

Your original decision was not necessarily wrong. The software changed.

Browser Extension Security FAQ

Can a trusted extension become malware?

Yes. An extension can be legitimate when you install it and later receive malicious functionality through an update, especially if ownership or developer control changes. The 2026 campaign analyzed by Socket included extensions that researchers said had been purchased from legitimate developers and later weaponized.

Should I disable extension updates?

Usually, no. Automatic updates are important because they deliver security patches, bug fixes, and compatibility improvements, and disabling them broadly can create other security problems. A better approach is to keep legitimate extensions updated while periodically reviewing what remains installed and what access those extensions have.

Are Chrome Web Store extensions safe?

The Chrome Web Store provides security checks, policies, reviews, and enforcement that make it a better source than unknown download websites. Even so, a store listing cannot guarantee that an extension’s code, ownership, permissions, infrastructure, or behavior will remain the same forever.

How often should I review extensions?

For most home users, checking installed browser extensions every few months is a practical schedule. You should also take another look whenever an extension unexpectedly changes its permissions, developer information, icon, name, behavior, or features.

What if I installed a bad extension?

Remove the extension, then consider what accounts and information it may have been able to reach while installed. If credential or session theft may have occurred, change affected passwords, sign out other active sessions where possible, enable multi-factor authentication, and check important accounts for activity you do not recognize.

Keep Checking What You Already Trust

Browser extensions are not something users need to panic about. Many are useful, well maintained, and completely legitimate, and automatic updates continue to play an important role in fixing security flaws and keeping software current. The lesson from this campaign is narrower and more practical: trust should not become permanent simply because an extension earned it once.

Software changes. Developers change. Products get sold. New code gets published, servers move, and features evolve. Most of those changes are normal and harmless. Occasionally, they are not. That is why checking an extension before installation is only part of the job.

Every so often, look at what is already sitting in your browser. Remove what you no longer need, question permissions that seem unusually broad, and investigate changes that do not make sense. Businesses should apply the same idea across company computers instead of allowing years of forgotten browser software to accumulate.

Microsoft offers similar site-access controls for Edge extensions, allowing users to control whether an extension can access a site when clicked, on particular websites, or across all sites. Those controls are worth reviewing when an extension does not need access everywhere.

The extension you trusted last year may still be perfectly fine today. In most cases, it probably is. The point is simply not to assume that trust lasts forever without ever checking again.

Related Articles

Browser Security: Passwords, Cookies & Extensions

Learn how browser extensions, passwords, cookies, and security settings affect your privacy and what you can do to reduce common browser risks.

Safe Software Checklist: Avoid Bad Apps

Learn what to check before installing software, including developers, permissions, warning signs, and other clues that can help you avoid risky apps.

Supply Chain Attacks: Risks and Defenses

See how attackers can exploit trusted software, vendors, and update channels, and learn practical ways to reduce software supply-chain security risks.

How Browser Extensions Can Hide Malware

See how malicious Firefox extensions concealed harmful code inside image files, revealing another way seemingly normal browser add-ons can hide malware.

Published on September 2, 2026 at 8:56 AM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.