My analysis of recent threats reveals a troubling trend: attackers are increasingly targeting users through seemingly harmless browser extensions. During an in-depth investigation, I managed to identify 18 malicious add-ons for Google Chrome and one more for Microsoft Edge that not only steal data but systematically drain cryptocurrency wallets. This is a genuine epidemic affecting tens of thousands of people worldwide, and Russian users, unfortunately, find themselves at the very epicenter of these events.

Scale of Infection and Attack Vector

The combined audience of just two versions of one of the most dangerous extensions reached 80,000 people. For example, the plugin Enable Right Click & Copy — Smart Unlock + OCR managed to infect over 70,000 Chrome users and about 10,000 Edge users before being removed from the store. These figures are alarming, especially given that the first traces of malicious activity were recorded back in 2024.

The attack mechanics are meticulously planned. Attackers do not create a threat from scratch but act more cunningly: they purchase legitimate extensions from their original developers and then inject malicious code through automatic updates. This means that at the time of installation, the extension may be completely clean, and the "time bomb" activates later, once the user's trust has already been won.

How the Malware Works

After installation, the program establishes an encrypted WebSocket connection with command-and-control (C2) servers and downloads modular JavaScript scripts. These modules are capable of much: they strip Content Security Policy protections from websites, inject hidden HTML elements, and intercept data entered on crypto exchanges and online services. Particularly dangerous is the malware's ability to replace "Connect Wallet" and "Swap" buttons, as well as create phishing pages mimicking the interfaces of Ledger and Trezor hardware wallets to extract seed phrases.

Nearly all popular platforms have been affected: Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, as well as MetaMask. The malicious code steals assets and account credentials in the background without disrupting the extension's stated functionality, so users may remain unaware of the infection for a long time. Additionally, fake browser system notifications are used to further deepen the attack.

Protection Recommendations

To anyone who may have installed infected extensions, I strongly advise treating their data as compromised and immediately changing passwords. If assets were stored in affected wallets, they must be transferred to new addresses. Regularly review the list of installed extensions and remove anything suspicious. Pay special attention to those requesting excessively broad permissions.

In today's reality, security is not just about installing antivirus software but maintaining constant vigilance. Any third-party extension is a potential entry point for attackers, so my advice to you: minimize their number and trust only time-tested solutions from official developers.