My analysis of recent cybersecurity data has revealed a troubling trend: a large network of malicious add-ons targeting cryptocurrency users has been discovered in browser extension stores. This involves 18 extensions for Google Chrome and one for Microsoft Edge, which operate like digital "vacuum cleaners," draining funds from wallets and stealing confidential data.
The scale of the threat is impressive. The combined audience of two versions of one of the most popular malicious extensions reached 80,000 people, and Russian users, unfortunately, have also fallen within the affected zone. These numbers are just the tip of the iceberg, as many victims may not even suspect they have been compromised.
Attack Mechanics: From "Harmless" Code to Full Control
The distribution scheme is particularly insidious. Five of the sixteen extensions were originally legitimate tools. Attackers purchased them from developers and then injected malicious code through automatic updates. This means that users who had trusted an extension for months suddenly became victims without any suspicious actions on their part.
One striking example is the extension Enable Right Click & Copy — Smart Unlock + OCR, which functioned in both Chrome and Edge. By the time the infection was discovered, its base in Chrome exceeded 70,000 users, while in Edge it was about 10,000. These extensions have now been removed from the Chrome Web Store, but the Edge version, according to my data, may still have remained available in the Microsoft Store.
Theft Technologies: From WebSocket to Fake Pages
The malicious code operates according to a well-honed scheme. After installation, it opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. These modules are capable not only of stealing passwords and browser history but also of draining EVM, Solana, and Tron wallets. To do this, they replace the "Connect Wallet" and "Swap" buttons with phishing ones, and also create fake pages to extract seed phrases, imitating Ledger and Trezor sites.
According to my data, the malicious modules target the theft of assets and data from the largest exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, as well as from MetaMask. In effect, all popular methods of storing and exchanging cryptocurrency are under threat.
Other Threats and Recommendations
Alongside this campaign, I am recording the growth of other schemes. Scammers are actively creating fake AML services for address verification that siphon funds from gullible asset owners. Additionally, hackers are exploiting vulnerabilities in operating systems, such as the "Screen Sharing" feature in macOS, to gain unauthorized access to computers.
To anyone who suspects they have infected extensions, I strongly recommend treating their data as compromised and immediately changing passwords. For those who stored cryptocurrency in affected wallets — transfer assets to new addresses. Regularly checking the list of installed extensions and being wary of requests for broad permissions are basic but vital precautions.
My expert opinion: This attack is a vivid example of how the software supply chain is becoming the primary attack vector. It is impossible to fully protect yourself, but you can minimize risks by installing only the minimally necessary extensions from verified developers and monitoring their updates. In the current reality, caution is the only truly reliable insurance.