Scammers have found yet another sophisticated way to get to users' digital assets. During my analysis of the threat landscape, a major campaign targeting visitors to the Chrome Web Store and the Microsoft Edge add-on store has been uncovered. This involves 18 malicious browser extensions for Google and one for Edge that not only steal data but also deliberately drain cryptocurrency wallets.

The combined audience of the two versions of one of the most dangerous extensions has reached 80,000 people. Russian users, who actively install such software for everyday tasks, have also been affected. These extensions masquerade as useful utilities but, in the background, load a modular framework designed to steal seed phrases, passwords, and browser history. The first traces of malicious activity date back to 2024, indicating a long-running and well-planned operation.

Attack mechanics and scale of infection

A distinctive feature of this scheme is "trojanization" through updates. Five of the sixteen extensions were originally legitimate. The attackers bought them from developers and injected malicious code only after they had gained popularity. For example, the extension Enable Right Click & Copy - Smart Unlock + OCR, which works in Chrome and Edge, was infected when its user base in Chrome exceeded 70,000 and in Edge around 10,000. Users continued to use the familiar functionality, unaware that their data was leaking into the hands of the attackers.

After installation, the program opens an encrypted WebSocket connection to a command-and-control (C2) server and downloads additional JavaScript modules. The malicious code disables Content Security Policy (CSP) protection on websites and injects hidden HTML elements to intercept data. Of particular danger is that the modules can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Additionally, phishing pages mimicking Ledger and Trezor interfaces are created to extract seed phrases.

Victims include users of the largest exchanges—Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit—as well as owners of the MetaMask wallet. To throw users off the scent, the extensions display advertising banners and fake browser update notifications, prompting the user to deepen the infection.

Other threat vectors and recommendations

Alongside this campaign, other schemes are also being recorded. Scammers create fake AML services for checking crypto addresses for involvement in money laundering, through which they trick users into granting access to their assets. A vulnerability in the "Screen Sharing" feature of Apple's macOS operating system is also being exploited, allowing hackers to gain unauthorized access to victims' computers.

To anyone who suspects they have infected extensions, I strongly recommend immediately treating their data as compromised and changing passwords. If you stored cryptocurrency in affected wallets—transfer the assets to new addresses. Regularly review your list of installed extensions and be cautious of those requesting broad permissions.

My expert opinion: This attack is a clear example that trust in extension stores should be measured. Even popular software can be compromised. In the current reality, the security of crypto assets depends 90% on the user's own hygiene, not on platform protection mechanisms. Installing a minimal number of extensions and using hardware wallets for large sums is not paranoia but a necessary precaution.