A large-scale cryptocurrency theft campaign has been uncovered in browser extensions. This involves 18 malicious add-ons for Google Chrome and one for Microsoft Edge that quietly drain wallets and steal user credentials. The combined audience of just two versions of one of these extensions reached 80,000 people, and Russian users are also among those at risk.

During a detailed analysis conducted by cybersecurity experts, an alarming trend was discovered: attackers are increasingly targeting users through seemingly legitimate browser tools. These extensions do not just display ads—they load a modular framework aimed at stealing seed phrases, passwords, and browsing history. The first traces of this activity date back to 2024, indicating a long-running and well-planned operation.

Why these extensions are dangerous for Russians

The attack mechanism is universal and knows no geographic boundaries. The malicious add-ons intercept data that users enter on any websites, including passwords for Facebook (owned by Meta, recognized as extremist and banned in the Russian Federation) and LinkedIn (blocked in Russia). They also collect browsing history. Thus, Russian cryptocurrency holders are at risk just like everyone else as soon as they install an infected extension.

Particularly dangerous is the fact that some of the discovered add-ons did not contain malicious code at the time of publication in the Chrome Web Store. Five of the sixteen extensions were purchased from their original developers and infected through automatic updates. This means that malicious functions are added gradually, as needed, allowing them to bypass standard security checks.

One such extension—Enable Right Click & Copy - Smart Unlock + OCR—worked in both Chrome and Edge. By the time it was infected, its base in Chrome exceeded 70,000 people, while in Edge it was about 10,000.

Although all discovered extensions have already been removed from the Chrome Web Store, the Edge version, according to available data, remained available in the Microsoft Store.

How the malware works

After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and downloads JavaScript modules. It then strips Content Security Policy (CSP) headers from visited websites and injects malicious scripts through hidden HTML elements. This allows it to intercept data on crypto exchanges and other online services.

The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Fake pages mimicking the websites of Ledger and Trezor hardware wallets are also created to lure out seed phrases. A separate feature involves fake browser update notifications that push victims toward actions deepening the infection. This entire process happens unnoticed by the user: externally, the extension performs its stated task, while the theft occurs in the background.

Other threats to cryptocurrency holders

In addition to browser extensions, experts also warn of a new phishing scheme. Scammers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset holders. In another case, hackers exploited an IT vulnerability in the "Screen Sharing" feature of Apple's macOS operating system, gaining unauthorized access to victims' computers through it.

Experts advise being careful about the browser extensions you install. Particular caution should be exercised with add-ons that request broad permissions. Regularly checking the list of active extensions is a useful habit that helps you notice a suspicious add-on in time and remove it before it causes damage. Combining these measures reduces the risk of losing funds and credentials. However, only caution when installing any third-party add-ons can fully protect you.

Analyst's opinion: This attack is yet another reminder that even "trusted" extensions can become a Trojan horse. The market is moving toward a model where security must be built into every click. I recommend that users use hardware wallets for long-term storage and minimize the number of installed browser plugins, especially those that have access to the content of all websites.