[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgUAmojWOIV3UDAQxoJVKoSe4zl8qw69ZPpi7mR6LCxo":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"ab9dda11-19fe-4995-94f8-5a3858f61718","Socket Now Protects the Microsoft Edge Extension Ecosystem","socket-now-protects-the-microsoft-edge-extension-ecosystem-55b921","Today, Socket is expanding browser extension security to Microsoft Edge. Enterprise security teams can now evaluate extensions published through Microsoft Edge Add-ons and monitor new releases for malicious behavior, excessive permissions, data collection, suspicious infrastructure, and changes that introduce new risk. This brings the same code and behavioral analysis already available for Chrome and Firefox to Microsoft’s extension ecosystem. Socket examines what an extension can access, what its code actually does, where it communicates, and how each release differs from the version an organization previously reviewed. # Microsoft Edge Add-ons contains more than 32,000 active extensions. Because Microsoft Edge uses Chromium extension APIs, much of the same extension code can run in both Edge and Chrome. Microsoft also allows Edge users to install extensions from the Chrome Web Store, in addition to extensions published through Microsoft Edge Add-ons. That flexibility gives users a larger selection of extensions, but it makes enterprise oversight more complicated. Two employees using Edge may have installed similar tools from different stores, under different extension IDs, with different publishers and update histories. A removal from one store does not automatically resolve the corresponding risk in another. Microsoft provides policies that let administrators allow, block, or force-install extensions. Those controls determine which extensions may run. Socket adds continuous analysis after approval, because the version reviewed six months ago may not be the version running today. An Extension Can Change Hands Without Warning # Most people install an extension once and never think about who owns it again. If the developer sells it, users do not receive a notification that someone new now controls its updates. The extension can keep the same name and identity, along with the users and permissions it has already accumulated. For an attacker, buying an extension means buying a ready-made distribution channel. Instead of convincing thousands of people to install an unfamiliar tool, the new owner can push an update to people who already trust it. That tactic was central to our latest browser extension threat research. Socket researchers identified 18 malicious Chrome extensions and one Edge extension delivering an extensible malware framework. Five had been purchased from legitimate developers and turned malicious through later updates. The other 14 were created by the threat actor, launched with clean functionality, and updated with malware after attracting users. One of the purchased extensions, “Enable Right Click & Copy — Smart Unlock + OCR,” had around 70,000 Chrome users when malicious functionality appeared. A version carrying the same malware had another 10,000 users on Edge. Together, the two listings created a potential exposure of 80,000 users, although that does not mean every user installed the malicious version. The Edge Version Stayed Live After Chrome Removed It # By the time of our investigation, the Chrome listing had been removed. The Edge version was still active and serving malware. After the Chrome extension was identified as malicious, the attackers published an Edge update with a new command-and-control domain on August 14, 2026. The difference between the two stores gave the attacker another path to keep the operation running. A Chrome takedown was an important intervention, but it did not protect Edge users who had installed the related extension through Microsoft’s store. The payloads also went far beyond a single wallet-stealing script. Our researchers found 16 modules, including a multi-chain wallet drainer, Ledger and Trezor recovery-phrase phishing, credential and form theft, crypto exchange session harvesting, browser-history exfiltration, and a fake Chrome update that instructed victims to run an attacker-supplied command. Microsoft’s Edge Add-ons policies prohibit malware, phishing, obfuscated code, and unauthorized remote scripts. Those policies provide an important baseline. The active Edge listing demonstrates why organizations also need continuous analysis of published code and every subsequent update. What Socket Detects in Microsoft Edge Extensions # Socket proactively analyzes extensions in Microsoft Edge Add-ons and continues monitoring new versions after publication. For each extension, security teams can investigate: Malicious behavior: Detect malware, credential and clipboard theft, data exfiltration, remote code and content loading, obfuscation, impersonation, and other unwanted behavior. Permissions and access: Review extension metadata, requested permissions, and the specific files and behaviors behind each alert. Network activity: Identify command-and-control infrastructure, suspicious endpoints, remote payload sources, and changes in the domains an extension contacts. Version changes: Compare releases under the same extension identity and surface meaningful differences in code, permissions, network activity, and behavior. Related activity: Connect extensions through reused code, shared infrastructure, publisher patterns, and coordinated campaigns. Permissions are an important part of extension review, but they do not reveal intent on their own. The malicious Edge extension in our recent research used its access to strip Content Security Policy headers from visited pages, maintain a persistent WebSocket connection to attacker infrastructure, and execute modules delivered remotely by the C2 server. Understanding that behavior requires analysis beyond the manifest. Socket gives security teams the evidence behind each finding so they can distinguish a legitimate use of a powerful browser API from code designed to steal data or maintain remote control. Consistent Coverage Across Chrome, Firefox, and Edge # With Microsoft Edge support, Socket now gives organizations a consistent way to evaluate extension risk across Chrome, Firefox, and Edge. Security teams can use the same detections and investigation workflow across all three ecosystems instead of relying on separate permission lists, store metadata, and one-time reviews. Chrome coverage analyzes extensions from the Chrome Web Store, including Chrome extensions that Edge users are permitted to install. Edge coverage adds extensions distributed through Microsoft Edge Add-ons, closing the store-specific gap exposed by our latest research. This gives organizations a clearer answer to the questions that matter after an extension is approved: What is installed? What can it access? What does the current version do? What changed in the latest update? Is it connected to other suspicious extensions or infrastructure? Available Today # Microsoft Edge extension protection is now available in Experimental to Socket enterprise customers. The release covers extensions published through the official Microsoft Edge Add-ons store and includes the same detections available across Socket’s existing browser extension security coverage. Enterprise customers can reach out to their Socket account team to enable Edge coverage. Organizations interested in evaluating Socket for browser extension security can contact us to get started.","Socket has expanded its browser extension security analysis to include Microsoft Edge. This new feature allows enterprise security teams to evaluate extensions published on Microsoft Edge Add-ons and monitor them for malicious behavior, excessive permissions, and suspicious network activity. The service aims to provide continuous analysis, addressing the risk of extensions being sold to malicious actors and updated with harmful code, a tactic highlighted by recent research involving malicious Chrome and Edge extensions.","Socket now offers Microsoft Edge extension security analysis for enterprise teams.","Back[Product]Socket Now Protects the Microsoft Edge Extension EcosystemEnterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.John TucknerAug 28, 2026|5 min readToday, Socket is expanding browser extension security to Microsoft Edge. Enterprise security teams can now evaluate extensions published through Microsoft Edge Add-ons and monitor new releases for malicious behavior, excessive permissions, data collection, suspicious infrastructure, and changes that introduce new risk.This brings the same code and behavioral analysis already available for Chrome and Firefox to Microsoft’s extension ecosystem. Socket examines what an extension can access, what its code actually does, where it communicates, and how each release differs from the version an organization previously reviewed.Edge Security Crosses Extension Store Boundaries#Microsoft Edge Add-ons contains more than 32,000 active extensions. Because Microsoft Edge uses Chromium extension APIs, much of the same extension code can run in both Edge and Chrome. Microsoft also allows Edge users to install extensions from the Chrome Web Store, in addition to extensions published through Microsoft Edge Add-ons.That flexibility gives users a larger selection of extensions, but it makes enterprise oversight more complicated. Two employees using Edge may have installed similar tools from different stores, under different extension IDs, with different publishers and update histories. A removal from one store does not automatically resolve the corresponding risk in another.Microsoft provides policies that let administrators allow, block, or force-install extensions. Those controls determine which extensions may run. Socket adds continuous analysis after approval, because the version reviewed six months ago may not be the version running today.An Extension Can Change Hands Without Warning#Most people install an extension once and never think about who owns it again. If the developer sells it, users do not receive a notification that someone new now controls its updates. The extension can keep the same name and identity, along with the users and permissions it has already accumulated.For an attacker, buying an extension means buying a ready-made distribution channel. Instead of convincing thousands of people to install an unfamiliar tool, the new owner can push an update to people who already trust it.That tactic was central to our latest browser extension threat research. Socket researchers identified 18 malicious Chrome extensions and one Edge extension delivering an extensible malware framework. Five had been purchased from legitimate developers and turned malicious through later updates. The other 14 were created by the threat actor, launched with clean functionality, and updated with malware after attracting users.One of the purchased extensions, “Enable Right Click & Copy — Smart Unlock + OCR,” had around 70,000 Chrome users when malicious functionality appeared. A version carrying the same malware had another 10,000 users on Edge. Together, the two listings created a potential exposure of 80,000 users, although that does not mean every user installed the malicious version.The Edge Version Stayed Live After Chrome Removed It#By the time of our investigation, the Chrome listing had been removed. The Edge version was still active and serving malware. After the Chrome extension was identified as malicious, the attackers published an Edge update with a new command-and-control domain on August 14, 2026.The difference between the two stores gave the attacker another path to keep the operation running. A Chrome takedown was an important intervention, but it did not protect Edge users who had installed the related extension through Microsoft’s store.The payloads also went far beyond a single wallet-stealing script. Our researchers found 16 modules, including a multi-chain wallet drainer, Ledger and Trezor recovery-phrase phishing, credential and form theft, crypto exchange session harvesting, browser-history exfiltration, and a fake Chrome update that instructed victims to run an attacker-supplied command.Microsoft’s Edge Add-ons policies prohibit malware, phishing, obfuscated code, and unauthorized remote scripts. Those policies provide an important baseline. The active Edge listing demonstrates why organizations also need continuous analysis of published code and every subsequent update.What Socket Detects in Microsoft Edge Extensions#Socket proactively analyzes extensions in Microsoft Edge Add-ons and continues monitoring new versions after publication. For each extension, security teams can investigate:Malicious behavior: Detect malware, credential and clipboard theft, data exfiltration, remote code and content loading, obfuscation, impersonation, and other unwanted behavior.Permissions and access: Review extension metadata, requested permissions, and the specific files and behaviors behind each alert.Network activity: Identify command-and-control infrastructure, suspicious endpoints, remote payload sources, and changes in the domains an extension contacts.Version changes: Compare releases under the same extension identity and surface meaningful differences in code, permissions, network activity, and behavior.Related activity: Connect extensions through reused code, shared infrastructure, publisher patterns, and coordinated campaigns.Permissions are an important part of extension review, but they do not reveal intent on their own. The malicious Edge extension in our recent research used its access to strip Content Security Policy headers from visited pages, maintain a persistent WebSocket connection to attacker infrastructure, and execute modules delivered remotely by the C2 server. Understanding that behavior requires analysis beyond the manifest.Socket gives security teams the evidence behind each finding so they can distinguish a legitimate use of a powerful browser API from code designed to steal data or maintain remote control.Consistent Coverage Across Chrome, Firefox, and Edge#With Microsoft Edge support, Socket now gives organizations a consistent way to evaluate extension risk across Chrome, Firefox, and Edge.Security teams can use the same detections and investigation workflow across all three ecosystems instead of relying on separate permission lists, store metadata, and one-time reviews. Chrome coverage analyzes extensions from the Chrome Web Store, including Chrome extensions that Edge users are permitted to install. Edge coverage adds extensions distributed through Microsoft Edge Add-ons, closing the store-specific gap exposed by our latest research.This gives organizations a clearer answer to the questions that matter after an extension is approved: What is installed? What can it access? What does the current version do? What changed in the latest update? Is it connected to other suspicious extensions or infrastructure?Available Today#Microsoft Edge extension protection is now available in Experimental to Socket enterprise customers. The release covers extensions published through the official Microsoft Edge Add-ons store and includes the same detections available across Socket’s existing browser extension security coverage.Enterprise customers can reach out to their Socket account team to enable Edge coverage. Organizations interested in evaluating Socket for browser extension security can contact us to get started.","https:\u002F\u002Fsocket.dev\u002Fblog\u002Fedge-extension-security?utm_medium=feed","https:\u002F\u002Fcdn.sanity.io\u002Fimages\u002Fcgdhsj6q\u002Fproduction\u002F741976bab49e670d415982ac2a513aff7ad45b47-2400x1260.png?w=1000&q=95&fit=max&auto=format","2026-08-28T13:22:10.334+00:00","2026-08-28T16:00:25.400877+00:00",7,[18,21,24,26,28,30],{"name":19,"type":20},"Microsoft Edge","product",{"name":22,"type":23},"Microsoft","vendor",{"name":25,"type":20},"Chrome",{"name":27,"type":20},"Firefox",{"name":29,"type":20},"Enable Right Click & Copy — Smart Unlock + OCR",{"name":31,"type":23},"Socket","02371804-cf6d-4449-98de-f1a2d4d9b266",{"id":32,"icon":34,"name":35,"slug":36},null,"Tools","tools",[38,40,45,50],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]