Threat Actor Weaponizes 70,000-User Chrome Extension for Fake Update Scams
Updated
Updated · Fox News · Aug 31
Threat Actor Weaponizes 70,000-User Chrome Extension for Fake Update Scams
3 articles · Updated · Fox News · Aug 31
Summary
Socket researchers said the once-legitimate “Enable Right Click & Copy” extension was acquired and updated with malicious code that pushed fake Chrome “Critical Update” warnings to users.
Around 70,000 users had the extension when the malicious functionality appeared, and Google delisted it from the Chrome Web Store on Aug. 14 after flagging it as potentially malicious.
Socket’s Aug. 27 research tied the case to a broader campaign spanning 19 Chrome and Edge extensions, with capabilities including credential theft, crypto-wallet draining, phishing-page injection and fake browser-update lures.
Recent user reviews — despite a roughly 4.7-star average rating — said disabling or removing the extension stopped the pop-ups, underscoring how old ratings can mask newly weaponized software.
Google says Chrome normally updates through the browser itself, so webpages urging downloads such as .vbs scripts or unfamiliar .exe files are a key warning sign of browser-based malware or hijacking.