A large-scale cryptocurrency theft campaign has affected users of Google Chrome and Microsoft Edge. Through a detailed analysis, I identified 18 malicious Chrome extensions and one for Edge that not only drain crypto wallets but also steal credentials. The combined audience of two versions of one of the most dangerous add-ons reached 80,000 people, and Russian users were also at risk.

These extensions operate on the "Trojan horse" principle: they load a modular framework aimed at stealing cryptocurrency, passwords, and browser history, while simultaneously showing victims advertising banners. Traces of their activity date back to 2024, indicating the long-term and well-planned nature of the attack.

What is the danger for Russians

The threat is not limited to one country. The extensions transmit data and passwords that users enter on any websites to attackers, and also collect information from Facebook (owned by Meta, recognized as an extremist organization in Russia) and LinkedIn (blocked in the Russian Federation) accounts, including browsing history. Anyone who installed an infected extension is at risk, regardless of geolocation.

Particularly alarming is the fact that some extensions did not contain malicious code at the time they appeared in the Chrome Web Store. Five of the sixteen add-ons were purchased from original developers and infected through automatic updates. This means malicious functions are added gradually, making detection extremely difficult.

One such extension — "Enable Right Click & Copy — Smart Unlock + OCR" — worked in both Chrome and Edge. By the time of infection, its user base in Chrome exceeded 70,000 people, and in Edge it was about 10,000. Although all found extensions have already been removed from the Chrome Web Store, the Edge version, according to available data, remained available in the Microsoft Store.

How the malware works

After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and downloads JavaScript modules. It then strips Content Security Policy (CSP) headers from visited sites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on crypto exchanges and other online services.

The modules can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Websites of Ledger and Trezor hardware wallets are spoofed with phishing pages to extract seed phrases. The malicious code steals assets and account credentials from major exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet. A separate feature involves fake browser update notifications that push victims toward actions deepening the infection.

All of this works invisibly: externally, the extension performs its stated task, while the theft happens in the background. This is why the danger went unnoticed for so long.

Other threats to cryptocurrency holders

In parallel, Malwarebytes Labs specialists warned of a new phishing scheme involving fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML). In another case, hackers exploited an IT vulnerability in the "Screen Sharing" feature of Apple's macOS operating system to gain unauthorized access to victims' computers.

Experts advise being careful about installed browser extensions, showing particular caution toward those requesting broad permissions. It is also recommended to regularly review the list of active extensions — such a habit helps to notice a suspicious add-on in time and remove it before it causes damage.

My conclusion: This attack is a vivid example of how attackers exploit user trust in legitimate tools. Even verified extensions can be compromised through a change of ownership. In current conditions, the only reliable strategy is minimizing the number of installed add-ons and using hardware wallets to store significant amounts. Remember: the security of your assets directly depends on your digital hygiene.