Package is invalid: CRX_HEADER_INVALID
The error string is the H1. Hash the file to see what you actually downloaded, then abandon sideload for the official Chrome listing.
Security Guides · 5 min · Updated Jul 2026 · Expert
Chrome’s CRX_HEADER_INVALID means the bytes are not a valid CRX package — a zip renamed to .crx, a truncated download, or garbage. It is not a hint to run a “CRX repair” tool on a wallet.
Hash the file below (preset rabby_chrome if you thought it was Rabby). Then install from rabby.io / the official ID instead of fighting the packager.
Do this now
- Do not run CRX fixers. Third-party “repair crx” utilities are malware magnets. Delete the file.
- Hash it only to identify the download. If SHA-256 matches a catalog wallet, you still install from the store, not by forcing the broken package.
- Use the official listing. Rabby:
acmacodkjbdgmoleebolmdjonilkdbch. Phantom and MetaMask IDs are on their download guides.
CRX_HEADER_INVALID → cause → fix
| Situation | Cause | Fix |
|---|---|---|
| Renamed .zip → .crx | Missing CRX header | Stop sideloading; store install |
| Download stopped at 20% | Truncated file | Re-download from vendor store, not the zip |
| Unpacked folder zipped | Not a CRX | Do not Load unpacked for custody wallets |
| Hashes do NOT match | Wrong or tainted file | mismatch |
What a “CRX repair” cannot do
It cannot turn a zip of a fake wallet into MetaMask. It cannot restore a store listing. Invalid header means stop.
This website will not generate a CRX for you.
Frequently asked questions
What does CRX_HEADER_INVALID mean?
Chrome rejected the package as not a valid CRX. Delete it. Install the wallet from the vendor’s Chrome Web Store listing and official ID.
Can I unzip the crx and load it unpacked?
Not as a user installing a custody wallet. That bypasses the store ID check that is the whole point.
Should I hash a file that already failed CRX_HEADER_INVALID?
Yes if you want to know whether it matches a known catalog digest. No if you intend to install that same file. Identification ≠ permission to sideload.