I have discovered a troubling trend: malicious extensions targeting the theft of cryptocurrency assets and users' confidential data are being distributed in the extension stores of Google Chrome and Microsoft Edge browsers. During a detailed analysis conducted by security experts, 18 such extensions were identified for Chrome and one for Edge. The combined audience of two versions of one of the most dangerous extensions reached 80,000 people, and users from Russia were also among those at risk.
Infection Mechanics and Scope of the Threat
These extensions operate using a well-established scheme: they load a modular framework designed to steal passwords, bank card data, and cryptocurrency itself. The first traces of attackers' activity date back to 2024, indicating a prolonged and well-coordinated campaign.
Particularly dangerous is the fact that some extensions did not contain malicious code at the time of publication in the Chrome Web Store. The attackers purchased legitimate extensions from their developers and injected malicious functions through automatic updates. This is a classic example of a supply chain attack, where the user's trust in already installed software is used against them.
For example, the extension Enable Right Click & Copy — Smart Unlock + OCR, operating in Chrome and Edge, had a base of over 70,000 users in Chrome and about 10,000 in Edge by the time of infection. Although all detected extensions have already been removed from the Chrome Web Store, the Edge version, according to available data, remained available in the Microsoft store.
How the Malware Works
After installation, the extension establishes an encrypted WebSocket connection with a command-and-control (C2) server and downloads additional JavaScript modules. It removes Content Security Policy (CSP) headers from visited websites and injects malicious scripts through hidden HTML elements. This allows interception of data entered on cryptocurrency exchanges and other online services.
The modules are capable of draining wallets on EVM, Solana, and Tron networks by replacing the "Connect Wallet" and "Swap" buttons. Additionally, phishing pages are created that mimic the websites of Ledger and Trezor hardware wallets to extract seed phrases. The malicious code steals assets and account data from major exchanges, including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, as well as from the MetaMask wallet.
A separate function involves fake browser update notifications, through which the victim is pushed toward actions that deepen the infection. Externally, the extension continues to perform its stated task, making the theft unnoticeable to the user.
Additional Threats and Recommendations
In addition to this campaign, experts are recording a rise in phishing schemes involving fake AML address checks, as well as the use of IT vulnerabilities in macOS for unauthorized access to victims' computers. All users who had infected extensions installed are strongly advised to consider their data compromised, change passwords, and transfer assets to new addresses.
Regularly checking the list of installed extensions and maintaining a cautious attitude toward requests for broad permissions are basic but effective precautionary measures. Only a combination of vigilance and technical hygiene can minimize risks in the modern threat landscape.
My comment: This attack is a vivid example of the evolution of cyber threats, where attackers strike not through code vulnerabilities but through users' trust in the browser ecosystem. Investors should reconsider their approach to access management: use a separate browser or profile for cryptocurrency operations and minimize the number of installed extensions.