A large-scale cryptocurrency theft campaign has been uncovered in the browser extension ecosystem. During an in-depth analysis, specialists at the company Socket discovered 18 malicious add-ons for Google Chrome and one for Microsoft Edge that not only drain crypto wallets but also steal confidential credentials. The combined audience of two versions of one such extension reached 80,000 users, and Russian holders of digital assets were among those affected.
Infection Mechanics and Scope of the Threat
The malicious extensions load a modular framework designed to steal cryptocurrency, passwords, and browser history. At the same time, they disguise themselves as useful utilities by displaying advertising banners. Traces of the attackers' activity date back to 2024, indicating a long-running and well-planned operation.
The distribution tactics are particularly alarming. Five of the sixteen extensions were purchased from their original developers, after which malicious code was injected into them via automatic updates. This means that at the time of publication in the Chrome Web Store, they contained nothing suspicious, allowing them to bypass moderation. A striking example is the extension "Enable Right Click & Copy — Smart Unlock + OCR," whose user base exceeded 70,000 in Chrome and amounted to about 10,000 in Edge. All the found add-ons have already been removed from the Chrome Web Store, but the Edge version, according to available data, remained available in the Microsoft store.
Technical Details of the Attack
After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and downloads JavaScript modules. It strips Content Security Policy (CSP) headers from visited websites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on crypto exchanges and other online services.
The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. For hardware wallets such as Ledger and Trezor, phishing pages are created to lure out seed phrases. Additionally, the code steals assets and account data from major exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from MetaMask. A separate feature involves fake browser update notifications that push the victim toward actions deepening the infection. Externally, the extension continues to perform its stated task, so the theft goes unnoticed.
Expert Assessment and Recommendations
This is not the only threat. Attackers are also actively using fake AML services to check addresses and exploiting vulnerabilities in operating systems, such as the "Screen Sharing" feature in macOS. For anyone who suspects they have infected extensions, I strongly recommend treating their data as compromised and immediately changing their passwords. Cryptocurrency from affected wallets should preferably be moved to new addresses.
Regularly checking the list of active extensions is a simple yet critically important habit. Pay special attention to those that request broad permissions. In a world where the browser has become the main gateway to finances, caution when installing any third-party software is not paranoia but a necessary security measure.