A large-scale cryptocurrency theft campaign has been uncovered in popular browser extensions. This involves 18 malicious add-ons for Google Chrome and one for Microsoft Edge that not only drain wallets but also steal user credentials. The combined audience of two versions of one such extension reached 80,000 people, and Russian users were also among those at risk.
Through detailed analysis, I was able to determine that these extensions load a modular framework designed to steal cryptocurrency, passwords, and browser history. At the same time, they disguise themselves as useful utilities by displaying advertising banners to avoid raising suspicion. The first traces of this activity date back to 2024, indicating a long-running and well-planned operation.
Why the extensions are dangerous for Russians
These add-ons transmit data and passwords that users enter on any websites to attackers. Moreover, they collect information from Facebook accounts (owned by Meta, recognized as an extremist organization in Russia) and LinkedIn (blocked in Russia), as well as extract browsing history. The threat is not limited to one country — anyone who installed the infected extension is at risk, so Russians are exposed just like everyone else.
What is particularly alarming is that some of the add-ons found did not contain malicious code when they first appeared in the Chrome Web Store. Attackers purchased five of the sixteen extensions from their original developers and infected them through automatic updates. This means the modules expand: malicious functions are added as needed, making detection extremely difficult.
One such add-on — Enable Right Click & Copy — Smart Unlock + OCR — worked in Chrome and Edge. By the time it was infected, its user base in Chrome exceeded 70,000 people, while in Edge it was about 10,000. All the extensions found have already been removed from the Chrome Web Store, but the Edge version, according to available data, remained available in the Microsoft Store.
For those who had infected add-ons installed, I strongly recommend considering your data compromised and changing your passwords as soon as possible. Those who stored cryptocurrency in affected wallets should transfer their assets to new addresses.
How the malware works
After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. It then removes Content Security Policy (CSP) headers from visited websites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on crypto exchanges and other online services.
The modules can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Websites for Ledger and Trezor hardware wallets are spoofed with phishing pages to extract seed phrases. The malicious code steals assets and account data from major exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet. Virtually all popular methods of storing and exchanging cryptocurrency are at risk.
A separate feature involves fake browser update notifications. Through these, victims are pushed to perform actions needed by the attackers, thereby deepening the infection. All of this works unnoticed by the user: externally, the extension performs its stated task, while the theft happens in the background. This is why the danger went unnoticed for so long.
Other threats to cryptocurrency holders
In addition to extensions, my colleagues at Malwarebytes Labs recently warned about a new phishing scheme. Scammers create fake services for checking crypto addresses against money laundering and sanctions violations (AML), through which they deceive asset holders.
In another case, hackers exploited an IT vulnerability in the "Screen Sharing" feature of Apple's macOS operating system. Through it, they gained unauthorized access to victims' computers.
Experts advise being careful about the browser extensions you install. Particular caution should be exercised with add-ons that request broad permissions. I also recommend regularly checking the list of active extensions — such a habit helps you notice a suspicious add-on in time and remove it before it causes damage.
A combination of these measures reduces the risk of losing funds and credentials. However, only caution when installing any third-party add-ons can fully protect you.
My expert commentary: This attack is a striking example of the evolution of cyber threats in the crypto industry. Attackers no longer hack protocols; they attack the weakest link — the user and their trust in legitimate software. In an environment where extensions can be compromised after the fact, I advise minimizing the number of installed browser add-ons and using hardware wallets to store significant amounts. Regularly auditing your digital habits is not paranoia but necessary hygiene in the modern world.