A large-scale campaign to steal cryptocurrency and personal data through browser extensions has been uncovered by analysts at Socket. The investigation found 18 malicious add-ons for Google Chrome and one for Microsoft Edge. The combined audience of two versions of one of the most dangerous extensions reached 80,000 users, and citizens of Russia were also among those at risk. The situation is compounded by the fact that attackers are acting with increasing sophistication, using modular infection schemes.

Attack mechanics: from a harmless plugin to full control

Notably, most extensions did not contain malicious code at the time they were published in the Chrome Web Store. Five of the sixteen add-ons were purchased from their original developers and infected through automatic updates. This means that users who installed a seemingly legitimate plugin received the malicious payload only after some time. The malicious modules, loaded via an encrypted WebSocket connection to command servers, are designed to steal passwords, browser history, and Facebook and LinkedIn account data.

One of the most telling examples is the Enable Right Click & Copy — Smart Unlock + OCR extension, which works in both Chrome and Edge. Its user base in Chrome exceeded 70,000 people, and in Edge about 10,000. All the discovered add-ons have already been removed from the Chrome Web Store, but the Edge version, according to available data, remained available in the Microsoft Store.

Technical details: how assets are stolen

After installation, the program removes Content Security Policy (CSP) headers from visited websites and injects malicious scripts through hidden HTML elements. This allows it to intercept data on cryptocurrency exchanges and other online services. The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Fake pages mimic the interfaces of Ledger and Trezor hardware wallets to extract seed phrases.

The malicious code steals assets and account data from the largest exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, as well as from the MetaMask wallet. Virtually all popular methods of storing and exchanging cryptocurrency are under threat.

A separate feature involves fake browser update notifications, through which the victim is pushed toward actions needed by the attackers, deepening the infection. All of this operates invisibly: outwardly, the extension performs its stated task, while the theft happens in the background.

Other threats to cryptocurrency holders

In parallel, specialists are recording new phishing schemes. Scammers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset holders. Additionally, hackers are actively exploiting vulnerabilities in the macOS operating system to gain unauthorized access to victims' computers.

Experts advise being careful about the extensions you install and regularly reviewing the list of active add-ons. Particular caution should be exercised with those that request broad permissions. Those who had infected plugins installed are recommended to consider their data compromised and change passwords as soon as possible, while those who stored cryptocurrency in affected wallets should transfer assets to new addresses.

Expert opinion: This attack is a striking example of the evolution of threats. Attackers no longer rely on "one-off" malware but instead create infrastructure for long-term and covert control. Every cryptocurrency user should view browser extensions as a potential attack vector and minimize their number, especially when dealing with finances.