Google Pulls 19 Extensions with Crypto Malware Identified by Socket
Nineteen Chrome and Edge extensions carried malware that targeted Solana, Tron, and EVM wallets for drainage and data theft; five were legitimate products later acquired by attackers.

Google removed 19 Chrome and Edge extensions that contained malware designed to drain cryptocurrency from Solana, Tron, and EVM-compatible wallets while also collecting passwords, personal data, browser history, and login details.
Socket researchers identified the campaign. Five of the extensions had begun as legitimate products that attackers later purchased and modified. The remaining 14 were created by the attackers, published without malicious code, and then updated after users installed them.
Scale and losses
Users who installed any of the affected extensions should treat their data as exposed and change relevant passwords. The exact number of affected users and any amounts drained have not been quantified, and no specific wallet addresses or loss figures have been disclosed.