A large-scale cryptocurrency theft campaign has been uncovered in popular browser stores. My analysis found 18 malicious extensions for Google Chrome and one for Microsoft Edge that drain crypto wallets and steal user credentials. The combined audience of two versions of one of these add-ons reached 80,000 people, and Russian users were also among those at risk.

Attack Mechanics: How Extensions Bypass Protection

These extensions load a modular framework designed to steal cryptocurrency, passwords, and browser history. On top of that, they show victims advertising lures. The first traces of attackers' activity date back to 2024. Particularly alarming is the fact that five of the sixteen extensions were purchased from original developers and infected via automatic updates—initially, they appeared in the Chrome Web Store as completely safe.

One of the most telling examples is the extension Enable Right Click & Copy — Smart Unlock + OCR, which works in Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 users, while in Edge it was about 10,000. All found add-ons have already been removed from the Chrome Web Store, but the Edge version, according to available data, remained available in the Microsoft Store.

Technical Details: From WebSocket to Site Substitution

After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. It then strips Content Security Policy (CSP) headers from visited sites and injects malicious scripts through hidden HTML elements. This allows it to intercept data on crypto exchanges and other online services.

The modules are capable of draining EVM, Solana, and Tron wallets by substituting the "Connect Wallet" and "Swap" buttons. Sites for Ledger and Trezor hardware wallets are spoofed with phishing pages to extract seed phrases. The malicious code steals assets and account data from major exchanges—Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit—as well as from the MetaMask wallet.

A separate feature involves fake browser update notifications that push victims toward actions deepening the infection. All of this operates invisibly to the user: externally, the extension performs its stated task, while the theft happens in the background.

Other Threats and Recommendations

Meanwhile, Malwarebytes Labs specialists warn of a new phishing scheme involving fake services that check crypto addresses for involvement in money laundering (AML). In another case, hackers exploited a vulnerability in macOS's "Screen Sharing" feature to gain unauthorized access to victims' computers.

For those who had infected add-ons installed, I strongly recommend considering your data compromised and immediately changing passwords. Those who stored cryptocurrency in affected wallets should transfer assets to new addresses. Regularly checking the list of active extensions and being cautious during installation are basic but critically important measures.

My comment: this attack is a vivid example of how cybercriminals monetize user trust in legitimate tools. The scheme of buying out extensions and subsequently infecting them via updates is especially dangerous because it undermines the very security model of browser stores. In the coming months, we should expect a rise in such campaigns, and investors need to rethink their digital hygiene habits.