A large-scale campaign to steal digital assets has been uncovered in browser stores. My fellow analysts have found 18 malicious extensions for Google Chrome and one for Microsoft Edge that are specifically designed to drain cryptocurrency wallets and steal users' confidential data. The combined audience of just one of these add-ons reached 80,000 people, and Russian users were among those affected.

The extensions, disguised as useful utilities, inject a modular framework into the browser aimed at stealing cryptocurrency, passwords, and browsing history. The first traces of their activity date back to 2024, indicating a long-running and carefully planned operation.

What is the main danger for users

These add-ons intercept data and passwords that victims enter on any websites, as well as collect information from social media accounts and browser history. The threat is global in nature: anyone who has installed an infected extension is at risk, regardless of their country of residence. Russians are at risk just like everyone else.

A key feature of this attack is the use of a legitimate distribution model. Some of the extensions did not contain malicious code at the time of publication in the Chrome Web Store. Five of the sixteen add-ons were purchased by the attackers from their original developers and infected through automatic updates. This means that malicious functions were added gradually, as needed, making them extremely difficult to detect.

For example, the extension Enable Right Click & Copy — Smart Unlock + OCR worked in Chrome and Edge. By the time it was infected, its user base in Chrome exceeded 70,000, and in Edge it was about 10,000.

All the extensions found have already been removed from the Chrome Web Store. However, the version for Edge, according to available data, remained available in the Microsoft store.

For those who have already installed the infected add-ons, I strongly recommend considering your data compromised and immediately changing your passwords. If you stored cryptocurrency in affected wallets, you need to transfer your assets to new addresses as soon as possible.

How the malware works

After installation, the program establishes an encrypted WebSocket connection to command-and-control (C2) servers and downloads JavaScript modules. It then disables Content Security Policy (CSP) headers on visited websites and injects malicious scripts through hidden HTML elements. This allows it to intercept data on crypto exchanges and other online services.

The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Phishing pages mimicking the sites of Ledger and Trezor hardware wallets are used to extract seed phrases. The malicious code steals assets and account data from major exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet.

A separate feature is fake browser update notifications. Through them, the victim is pushed to perform actions needed by the attackers, allowing even deeper penetration into the system. All of this works invisibly: externally, the extension performs its stated task, while the theft happens in the background.

Other threats for cryptocurrency owners

In addition to this campaign, security experts are warning about a new phishing scheme. Scammers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset owners.

In another case, hackers exploited a vulnerability in the "Screen Sharing" feature of Apple's macOS operating system, gaining unauthorized access to victims' computers through it.

Experts advise being careful about the browser extensions you install, showing particular caution toward those that request broad permissions. Regularly checking the list of active extensions is a useful habit that will help you notice a suspicious add-on in time and remove it before it causes damage.

My expert opinion: This attack demonstrates a worrying trend — attackers are increasingly using the "trojanization" of legitimate software through the supply chain. It is critically important for users to remember: even a popular extension with a good reputation can become dangerous after a change of ownership. Always check the update history and requested permissions.