Fake Chrome update scam could infect your computer
A Chrome extension called "Enable Right Click & Copy – Smart Unlock + OCR" was reportedly hijacked by a threat actor after starting out as a legitimate tool, before being used to push fake "Critical Update Required" browser pop-ups designed to trick users into installing malware. Security researchers at Socket found the extension, which had around 70,000 users, was delisted from the Chrome Web Store on 14 August after being flagged as malicious, and Google has confirmed it investigated the tool and taken action to protect users. The case highlights a broader risk: extensions installed safely months earlier can be changed for the worse after a change of ownership or a routine update, without users noticing.
Socket's research, published on 27 August, linked the extension to a wider campaign involving 19 Chrome and Edge extensions capable of stealing credentials, draining cryptocurrency wallets, injecting phishing pages and displaying fake update lures. Genuine Chrome updates are handled automatically by the browser itself or can be checked manually via More > Help > About Google Chrome, so any webpage prompting a download of a .vbs script or unfamiliar .exe file should be treated as suspicious. Google advises against installing software via pop-up warnings, recommending users go directly to the official program or website instead, and researchers note a similar pattern occurred earlier this year with another extension, QuickLens, which turned malicious after changing hands.
- Hijacked Chrome extension pushed fake "Critical Update" pop-ups to spread malware
- Extension had 70,000 users; delisted 14 August after being flagged
- Part of wider 19-extension campaign stealing credentials and crypto wallets