My analysis of fresh threat data reveals a troubling trend: attackers are increasingly targeting not through complex exploits, but through seemingly harmless browser extensions. This concerns a large-scale campaign in which 18 malicious extensions for Google Chrome and one for Microsoft Edge were discovered. These tools don't just spy—they directly drain crypto wallets and steal credentials.
Scope of the Threat and Geography of Attacks
The combined audience of just one version of the malicious extension reached 80,000 users, and Russian users were among those affected. This is not a targeted operation, but a wide-reaching network aimed at anyone who installed the infected software. What is most alarming is that the extensions, including Enable Right Click & Copy — Smart Unlock + OCR, are disguised as useful utilities. The user base of this particular extension exceeded 70,000 people in Chrome and about 10,000 in Edge.
Infection Mechanics: From Purchase to Update
A key feature of this attack is a multi-stage injection scheme. Five of the sixteen extensions were initially legitimate. Attackers bought them from developers and injected malicious code through automatic updates. This means that even a long-installed and trusted extension can become dangerous. The malicious logic is not activated immediately, but as needed, allowing it to remain undetected for a long time.
Technical Details and Attack Objectives
After installation, the program establishes an encrypted WebSocket connection to a command-and-control (C2) server and downloads JavaScript modules. These modules can strip Content Security Policy (CSP) protection from websites, intercept data on crypto exchanges, and replace wallet connection buttons. Nearly all popular platforms have been affected, from Coinbase and Binance to MetaMask. Moreover, attackers create fake pages for Ledger and Trezor hardware wallets to lure out seed phrases. All of this happens unnoticed by the user, who only sees a properly functioning extension.
Additional Attack Vectors
Alongside the extensions, other threats are also being recorded. Scammers are actively using fake AML services for address checks to trick users into granting wallet access. Additionally, a vulnerability in the "Screen Sharing" feature in Apple's macOS is being exploited, allowing unauthorized access to victims' computers. Together, these attacks create an extremely dangerous environment for digital asset holders.
My expert conclusion: The browser extension market has become a new "hot spot" for cybercriminals. Users need to reconsider their approach to installed software. Regularly reviewing the list of active extensions, critically analyzing requested permissions, and, most importantly, using hardware wallets to store significant amounts are not just recommendations, but necessary precautions in the current landscape. Software supply chain vulnerability is a systemic issue, and only the vigilance of each user can serve as an effective barrier.