19 Chrome Extensions Were Malware — Including SEO Tools Bloggers Use
Security researchers just identified 19 Chrome and Edge extensions that were secretly stealing browser history, login credentials, and crypto wallet data — and unlike most malware sweeps, several of the infected extensions are the exact SEO checker and ad-spy tools solo bloggers and affiliate marketers install every day, not random consumer utilities.
Key Takeaway: Researchers at Socket found that 14 of the 19 malicious extensions were built by attackers from scratch to look like useful tools, while the other 5 started life as legitimate extensions that attackers later bought from their original developers and quietly weaponized. Both Google and Microsoft have pulled all 19 from their stores, but removal from the store does not remove them from browsers that already installed them — you have to do that manually.
Most coverage of this story is treating it as a generic "check your Chrome extensions" warning. What's actually relevant if you run a blog or do affiliate marketing is that a chunk of the list is aimed at exactly your workflow.
What Actually Happened
According to Socket's research, reported by PCWorld on September 1, 2026, the malware campaign behind these 19 extensions had been running for roughly two years before it was caught. The extensions performed their advertised functions normally, which is exactly why they built up real user bases — one of them, "Enable Right Click & Copy – Smart Unlock + OCR," reached around 70,000 installs before it was pulled.
Once installed and trusted, the extensions were retrofitted with hidden code that intercepted browser history, login details, and cryptocurrency wallet tokens without any visible sign to the user. Because Chrome and Edge don't notify you when an extension you already have installed gets removed from the store, an infected extension can keep quietly running on your machine indefinitely unless you go check for it yourself.
The Part Most Coverage Is Missing: Several of These Are Blogger and Marketer Tools
Here's the full list, with the ones a publisher would actually install called out:
| Extension Name | Category | Relevant to Bloggers/Marketers? |
|---|---|---|
| Enable Right Click & Copy – Smart Unlock + OCR | Utility | Yes — commonly used for research |
| RapidLens – Google Lens for Screen Search & Images | Utility | Possible |
| QuickLens – Search Screen with Google Lens | Utility | Possible |
| Password Protect PDF | Utility | No |
| Allow Copy – Select & Enable Right-Click | Utility | Yes — commonly used for research |
| PixelCheck | Utility | No |
| Creative Library – Ad Spy Tool | Ad research | Yes — direct affiliate/ad marketer tool |
| Website Traffic Checker: MirrorSphere SEO Stats | SEO | Yes — direct blogger/SEO tool |
| Site Signal – Website Traffic & SEO Checker | SEO | Yes — direct blogger/SEO tool |
| SEO Pulse Pro – Website Traffic & SEO Analyser | SEO | Yes — direct blogger/SEO tool |
| Private Crypto News Reader | Crypto | Niche audience only |
| Blockfolio: Address Monitor | Crypto | Niche audience only |
| Crypto Rates & Fiat Converter | Crypto | Niche audience only |
| Crypto Alerter: Price Alerts & Volatility Warnings | Crypto | Niche audience only |
| DeFi Pulse Tracker | Crypto | Niche audience only |
| Crypto Price Badge: Quick Glance | Crypto | Niche audience only |
| Multi-Chain Explorer | Crypto | Niche audience only |
| LedgerLook: Wallet Checker | Crypto | Niche audience only |
| Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray | Ad research | Yes — direct affiliate/ad marketer tool |
If you've ever searched for "best SEO Chrome extensions" or "ad spy tool for affiliate marketing," it's genuinely possible you installed one of the five bolded extensions above. That's a very different risk profile than a random crypto price tracker — these tools often get pinned in the toolbar and used constantly, which means more exposure time for whatever was watching in the background.
How to Check If You're Affected
Removal from the Chrome Web Store or Edge Add-ons store does not uninstall anything from your browser automatically. You have to check manually.
Why "Bought Then Weaponized" Is the Part Worth Understanding
Five of these 19 extensions weren't malicious from day one — they were legitimate tools that built a real audience, then got sold to the attackers behind this campaign, who pushed an update carrying the malicious code. This is the same underlying pattern we covered in our breakdown of how to tell if your AI Chrome extension is stealing your data: an update from a "trusted" extension is not automatically safe just because you trusted the earlier version, because ownership itself can change hands quietly.
It also echoes the mechanics behind the 737 fake VPN Chrome extensions we reported on last month — a different campaign, but the same playbook of using a legitimate-sounding category (VPN tools there, SEO and ad-research tools here) to lower people's guard before the switch flips.
What to Use Instead
If you're removing one of the affected SEO or ad-spy tools, you don't have to go without the function — you just need to be more deliberate about the publisher. For SEO and traffic-checking, verify the developer's identity against their actual company website before installing a replacement, not just the extension's name and icon. For ad-spy research specifically, check whether the platform you're trying to research offers a native, no-extension way to do the same lookup before reaching for a third-party tool at all.
Pro Tip: Set a recurring reminder to audit every extension you have installed every few months, not just when you add something new. An extension that was safe and well-run a year ago can quietly change hands, exactly like several of the tools in this story did.
The Bottom Line
This isn't a story about avoiding sketchy corners of the internet — every one of these 19 extensions was distributed through the official Chrome and Edge stores and performed its advertised job correctly. If you run a blog, check competitor ads, or track your own SEO stats through browser extensions, this is worth five minutes of checking your extensions list today rather than assuming official-store distribution is enough of a safety net on its own.
Sourcing note: This article is based on security research from Socket, as reported by PCWorld on September 1, 2026. The full technical breakdown of how the malicious code operated has not been independently verified by Panstag beyond what Socket and PCWorld have published.
