A large-scale crypto-asset theft campaign has hit users of popular browsers. In a thorough analysis conducted by cybersecurity experts, 18 malicious extensions for Google Chrome and one more for Microsoft Edge were identified. These seemingly harmless add-ons not only drain cryptocurrency wallets but also steal confidential credentials. The combined audience of one such extension reached 80,000 people, and Russian users were also among those affected.

How the threat works

The attack mechanics are meticulously designed. The extensions load a modular framework intended to steal cryptocurrency, passwords, and browser history. Meanwhile, victims are shown advertising "bait" to divert attention from the background theft. The first traces of this activity were recorded back in 2024.

Particularly dangerous is the fact that some extensions were purchased by attackers from their original developers. Malicious code was not injected immediately but through automatic updates, allowing it to remain undetected for a long time. For example, an extension called "Enable Right Click & Copy — Smart Unlock + OCR" operated in both Chrome and Edge. By the time the infection was discovered, its base in Chrome exceeded 70,000 users, while in Edge it was about 10,000.

After installation, the program establishes an encrypted WebSocket connection with command-and-control (C2) servers and downloads JavaScript modules. These modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Moreover, phishing pages are created that mimic the sites of Ledger and Trezor hardware wallets to extract seed phrases. The malicious code steals data from major exchanges, including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, and Bybit, as well as from MetaMask.

Other threats and protective measures

In parallel with this campaign, there is a rise in phishing schemes using fake AML services for address verification. Hackers are also actively exploiting vulnerabilities in operating systems, such as the "Screen Sharing" feature in macOS, gaining unauthorized access to victims' computers.

To all users who may have had infected extensions installed, I strongly recommend considering your data compromised. It is necessary to immediately change passwords and transfer crypto assets to new, "clean" addresses. Regularly checking the list of installed extensions and being wary of requests for broad permissions are basic but critically important precautions.

My expert conclusion: this attack is a striking example of how cybercriminals adapt to users' trust in official app stores. The industry needs to rethink extension moderation and monitoring processes, focusing on behavior analysis after updates rather than just static code review. As for users, it is worth remembering: security is not a feature, but a habit.