5 minNews
Fake Chrome update scam linked to browser extension with 70,000 users
Security researchers have linked aggressive fake Chrome update warnings to a browser extension that was acquired by a threat actor and updated with malicious functionality. The extension, Enable Right Click & Copy - Smart Unlock + OCR, was delisted from the Chrome Web Store after being flagged as potentially malicious.
A convincing fake Chrome update scam has been traced to a browser extension that began as a legitimate tool before being acquired by a threat actor and updated with malicious functionality, according to security researchers at Socket. The extension, called Enable Right Click & Copy - Smart Unlock + OCR, was designed to restore right-click and copying features on websites that block them, but researchers say it was later weaponized to display aggressive fake update warnings.
The extension had approximately 70,000 users when the malicious functionality appeared, although researchers caution that not every user necessarily received the malicious version. Google delisted the extension from the Chrome Web Store on Aug. 14 after it was flagged as potentially malicious. A Google spokesperson confirmed to CyberGuy that the company investigated the extension and took action to protect users.
The scam works by displaying a warning that takes over the page while a user is browsing an otherwise normal website. The message claims a critical update is required before browsing can continue, using language such as "Critical Update Required" or "Update available." The alert then pushes the user to download something before proceeding. However, Chrome normally handles updates automatically in the background, and users can check manually by opening Chrome and navigating to More, then Help, then About Google Chrome.
Google advises users to avoid suspicious pop-ups asking them to install updates and instead recommends going directly to the program or its official website. A webpage asking a user to download a.vbs script or an unfamiliar.exe file to update Chrome should immediately raise suspicion.
New research published by Socket on Aug. 27 shows the threat extended beyond fake update warnings. Researchers linked the extension to a larger campaign involving 19 Chrome and Edge extensions capable of delivering malicious payloads, including credential theft, cryptocurrency wallet draining, injected phishing pages, and fake browser update lures. Socket says some of these extensions began as legitimate products before being acquired and weaponized by the threat actor.
This pattern has been seen before. Earlier this year, researchers found that another extension, QuickLens - Search Screen with Google Lens, changed ownership before a malicious update arrived. That extension had previously earned a Featured badge from Google. Researchers later found malicious functionality capable of injecting code, displaying fake Google update prompts, and targeting sensitive information. Google removed QuickLens from the Chrome Web Store.
CyberGuy has also reported on trusted browser extensions that later became spyware. One campaign affected 4.3 million users after extensions that began as useful tools eventually received malicious updates. The recent case involving Enable Right Click & Copy - Smart Unlock + OCR had another notable detail: the extension still had an average rating near 4.7 stars as reports of fake update warnings appeared. This can happen because thousands of earlier positive ratings remain part of the overall score while recent reviews begin filling with warnings.
In this case, August reviews accused the extension of injecting fake Chrome update alerts, and several users said removing or disabling it stopped the prompts. One Reddit user who encountered the fake update warnings said a full scan found nothing, but the user later traced the pop-ups to the Right Click extension. A clean scan should never convince a user that a suspicious browser warning is safe, because the extension itself may be creating or injecting what appears inside the browser, while a downloaded malicious file may pose a separate threat if opened or executed.
Google's Safe Browsing system checks installed extensions and downloads, but users are advised to look beyond overall star ratings before installing an extension and to read the newest reviews as well. The bigger lesson, researchers say, is that something installed months ago and trusted every day can change after an update.
