A large-scale crypto asset theft campaign has been uncovered in browser extensions. My analysis shows that 18 malicious add-ons for Google Chrome and one for Microsoft Edge have been detected, which not only drain wallets but also steal credentials. The combined audience of two versions of one of the most dangerous extensions reached 80,000 users, and Russians, unfortunately, fell within the affected zone alongside the rest of the world.
Infection Mechanics: A Trojan Horse in Updates
The key feature of this threat is the dynamic loading of malicious code. Five of the sixteen extensions were purchased by attackers from their original developers. Victims installed a seemingly legitimate plugin, and malicious functions were "delivered" later via automatic updates. This is a classic trust-based attack scheme that went unnoticed for years.
One of the most striking examples is the extension Enable Right Click & Copy — Smart Unlock + OCR, which works in Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 people, while in Edge it was about 10,000. All the discovered add-ons have now been removed from the Chrome Web Store, but the Edge version, according to my data, may still have remained available in the Microsoft Store.
What Exactly Is Stolen and How
After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and downloads JS modules. These modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Moreover, phishing pages imitating Ledger and Trezor are created to extract seed phrases. The malicious code intercepts data on crypto exchanges and in MetaMask, as well as steals passwords, browsing history, and Facebook and LinkedIn account data.
A separate feature is fake browser update notifications that push victims toward actions deepening the infection. Externally, the extension continues to perform its stated task, so the user does not notice the trick for a long time.
Other Threats and Precautionary Measures
In parallel with this campaign, specialists are recording a rise in phishing AML services that imitate address checks for involvement in money laundering. An exploitation of a vulnerability in the macOS "Screen Sharing" feature was also discovered, which gave hackers unauthorized access to victims' computers.
My advice: regularly review the list of installed extensions and ruthlessly remove those that request suspiciously broad permissions. If you used an infected plugin, consider all passwords compromised, and it is better to transfer crypto assets to new addresses. In a world where the browser has become the main gateway to finances, vigilance is the only reliable safe.