My fellow analysts at Socket have uncovered a troubling trend: 18 malicious extensions for Google Chrome and one for Microsoft Edge are actively being used to steal cryptocurrency and credentials from users worldwide, including Russians. The combined audience of two versions of one of the most dangerous add-ons has reached 80,000 people, making this threat one of the largest of the current year.
Attack Mechanics: From a Harmless Extension to Full Control
Malicious extensions, such as "Enable Right Click & Copy — Smart Unlock + OCR," operate on the "Trojan horse" principle. At the time of publication in the Chrome Web Store, they contained no malicious code. However, attackers purchased the extensions from their original developers and injected malicious functions through automatic updates. This means that even long-installed and "trusted" add-ons can become dangerous at any moment.
After installation, the extension opens an encrypted WebSocket connection to command-and-control (C2) servers and downloads JavaScript modules. It disables Content Security Policy (CSP) protection on visited sites and injects hidden HTML elements to intercept data. The malicious code is capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Moreover, it creates phishing pages that mimic Ledger and Trezor sites to lure out seed phrases.
Of particular danger is the theft of data from major exchanges—Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit—as well as from the MetaMask wallet. The extensions also intercept passwords entered on any websites and collect data from Facebook and LinkedIn accounts. All of this operates invisibly to the user: the extension continues to perform its stated functions while the theft occurs in the background.
Expert Analysis and Recommendations
Although all the discovered extensions have already been removed from the Chrome Web Store, the Edge version, according to available data, remained accessible in the Microsoft Store. For those who may have installed the infected add-ons, I strongly recommend immediately changing all passwords and transferring crypto assets to new addresses. Regularly reviewing the list of installed extensions and being cautious when granting permissions are basic but critically important security measures.
This attack is a striking example of how cybercriminals adapt to modern defense methods. They no longer hack websites but instead target user trust in legitimate tools. In a world where digital security is becoming increasingly fragile, the only reliable strategy is mindful caution and constant vigilance when working with any third-party software.