My analysis of fresh threat data reveals a troubling trend: 18 malicious extensions for Google Chrome and one more for Microsoft Edge have been discovered in browser stores, actively used to steal cryptocurrency and credentials. The combined audience of two versions of one of the most dangerous add-ons reached 80,000 users, and Russian holders of digital assets are among those affected. These are no longer isolated cases but a systematic scheme requiring immediate attention.

The attack mechanics are well-honed. Extensions disguised as useful utilities load a modular framework after installation, aimed at stealing seed phrases, passwords, and browser history. Meanwhile, victims are shown advertising banners to distract attention from background activity. The first traces of such activity have been recorded since 2024, meaning attackers have been operating for at least a year and a half.

Why this matters to users in Russia

The danger is not limited to one country—the extensions transmit data to command-and-control (C2) servers via encrypted WebSocket connections, after which they inject malicious scripts into websites. They strip Content Security Policy (CSP) protective headers and intercept data entered on crypto exchanges. Accounts on Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and the MetaMask wallet have been caught in the blast zone. Russian users are at risk just like everyone else, especially if they use browser extensions for everyday tasks.

Notably, five of the sixteen extensions were originally legitimate: attackers bought them from developers and added malicious code through automatic updates. This means that even a time-tested add-on can become a Trojan horse. For example, the Enable Right Click & Copy — Smart Unlock + OCR extension, operating in Chrome and Edge, had a base of 70,000 and 10,000 users respectively by the time it was infected. All discovered add-ons have already been removed from the Chrome Web Store, but the Edge version remained available in the Microsoft store.

How to protect yourself from the hidden threat

The malicious code can drain wallets on EVM, Solana, and Tron networks by swapping out the "Connect Wallet" and "Swap" buttons. It also creates fake pages mimicking Ledger and Trezor to lure out seed phrases. A separate feature involves fake browser update notifications that push users toward actions deepening the infection. All of this happens invisibly: externally, the extension performs its stated task, while the theft runs in the background.

For those who suspect they have installed such add-ons, I strongly recommend treating all data as compromised and immediately changing passwords. If assets were stored in affected wallets—transfer them to new addresses without delay. Regularly reviewing the list of installed extensions and being cautious when granting permissions are basic but critically important measures. Amid the rise of such attacks, including fake AML services and vulnerabilities in macOS, only vigilance can protect your funds from total loss.

My expert opinion: this campaign is a clear signal that browser extensions have become a new entry point for cybercriminals. The cryptocurrency market attracts increasingly sophisticated attackers, and investors should reconsider their habits: minimize the number of installed add-ons and use hardware wallets for long-term asset storage.