Ad End 1 August 2026
Adv exp at 7 December 2026
banner Expire 20 August 2026
banner Expire 15 January 2025
banner Expire 20 August 2026
ad End 17 September 2026
banner Expire 27 September 2026
adv exp at 20 OCtober  2026
What's new
 Ad expire at 26 September 2023
Ads end 31 October 2026
RonalClub cc shop
Patrick Stash
Luki Crown
Wizard's shop 2.0
best shop
Ads end 31 October 2026

Chrome Web Store Extensions caught stealing Crypto, Browser Data

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
8,109
Reaction score
1,117
Points
212
Awards
2
  • trusted user
  • Rich User
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures. Researchers say all 16 malicious modules uncovered in the campaign serve distinct purposes and are designed to be "highly extensible." The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024. Socket says that when initially published on the Chrome Web Store, many of the extensions provided the advertised functionality and contained no malware. According to the researchers, five of the extensions were acquired from their original creators and injected with malware via updates delivered automatically. One example is the "Enable Right Click & Copy — Smart Unlock + OCR" extension, the only one in the campaign available for both Chrome and Edge, which had a Chrome user base of at least 70,000 when it turned malicious. The number of installs on Edge was 10,000 at the time. Google caught the threat early and removed the extension from its add-ons marketplace, but at the time of Socket publishing its report, the Edge version remained available.


*malicious extensions available on the Edge add-ons store
Once installed, the malware establishes an encrypted WebSocket connection with command-and-control (C2) servers, downloads JavaScript modules, removes Content Security Policy (CSP) headers from every website visited, and injects malicious scripts into websites through hidden HTML elements. Socket observed malware modules with the following capabilities:
  • Draining EVM, Solana, and Tron wallets by hijacking legitimate “Connect Wallet” and “Swap” buttons
  • Replacing Ledger and Trezor websites with convincing seed-phrase phishing pages
  • Stealing sessions, tokens, account data, and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask
  • Recording credentials and form entries across websites
  • Harvesting Facebook and LinkedIn account information
  • Exfiltrating browser history
  • Displaying ClickFix-style fake browser updates that instruct victims to execute attacker-provided commands

*crypto wallet seed theft page.
Socket warns that the malicious framework may have more modules and that as the malware evolves over time, new payloads are expected to be deployed. At the time of publishing, none of the malicious extensions are available in the Chrome Web Store. Socket's report provides the full list of extension IDs uncovered in the campaign along with the domains used for C2 communication. Users who had any of the extensions installed should assume that their credentials have been compromised and change their login passwords. Cryptocurrency holders potentially impacted by this campaign are recommended to move their assets to a newly created wallet as soon as possible.
 
Ad End 1 November 2024
Top