A large-scale digital asset theft campaign has been uncovered in browser stores. I managed to detect 18 malicious extensions for Google Chrome and one for Microsoft Edge that not only steal credentials but also directly drain users' cryptocurrency wallets. The combined audience of two versions of one such add-on reached 80,000 people, and Russian users were among those affected.

Mechanics of the Hidden Threat

The extensions load a modular framework aimed at stealing cryptocurrency, passwords, and browser history. Externally, they perform their stated functions, such as enabling right-click or OCR recognition, but in the background they show victims advertising lures and collect sensitive data. The first traces of this activity date back to 2024.

What is particularly alarming is that some of the extensions were originally legitimate. Attackers purchased five of the sixteen add-ons from their original developers and then "infected" them through automatic updates. This means malicious code was added gradually, as needed, which allowed the attack to go unnoticed for a long time.

One of the most dangerous extensions — Enable Right Click & Copy — Smart Unlock + OCR — operated simultaneously in Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 users, while in Edge it was about 10,000. Although all discovered add-ons have already been removed from the Chrome Web Store, the Edge version, according to available data, may still have remained available in the Microsoft Store.

How the Malware Works

After installation, the extension opens an encrypted WebSocket connection to command-and-control (C2) servers and downloads JavaScript modules. It then strips Content Security Policy (CSP) headers from visited sites and injects malicious scripts through hidden HTML elements. This allows it to intercept data on crypto exchanges and other online services.

The modules can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Additionally, phishing pages are created that mimic Ledger and Trezor hardware wallet sites to extract seed phrases. The malicious code steals assets and account data from major exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet. A separate feature involves fake browser update notifications that push victims toward actions deepening the infection.

Other Threats to Cryptocurrency Holders

Meanwhile, new phishing schemes are being recorded. Attackers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset holders. Additionally, hackers are actively exploiting an IT vulnerability in the "Screen Sharing" feature of Apple's macOS operating system, gaining unauthorized access to victims' computers through it.

Victims need to consider their data compromised and change passwords as quickly as possible. For those who stored cryptocurrency in affected wallets, I strongly recommend transferring assets to new addresses. Regularly checking the list of installed extensions and being wary of those requesting broad permissions is a basic but critically important level of protection.

My comment: This attack is a vivid example of the evolution of threats: attackers no longer create malware from scratch but prefer to compromise trusted tools. This makes protection significantly harder, as users cannot distinguish a legitimate extension from an infected one. The only reliable strategy is minimizing the number of installed extensions and using hardware wallets to store significant amounts.