A large-scale campaign to steal crypto assets has hit users of Chromium-based browsers. Through in-depth analysis, I managed to identify 18 malicious extensions for Google Chrome and one for Microsoft Edge that not only drain wallets but also steal confidential data. The combined audience of two versions of one of the most dangerous add-ons reached 80,000 people, and Russian users were among those affected.

These extensions operate on a proven scheme: they load a modular framework aimed at stealing cryptocurrency, passwords, and browser history. On top of that, victims are shown advertising lures. The first traces of the attackers' activity date back to 2024, indicating a long and carefully planned operation.

Infection mechanics and the threat to Russians

The add-ons transmit data and passwords that users enter on any websites to the attackers, and also collect information from Facebook accounts (owned by Meta, recognized as an extremist organization in Russia) and LinkedIn (blocked in the Russian Federation), plus extract browsing history. The threat is not limited to one country: anyone who has installed an infected extension is at risk, so Russians are endangered just like everyone else.

A key feature is that some of the found extensions did not contain malicious code when they appeared in the Chrome Web Store. Five of the sixteen extensions were bought out by the attackers from their original developers and infected through automatic updates. This means the modules expand: malicious functions are added as needed.

One such add-on — Enable Right Click & Copy — Smart Unlock + OCR — worked in Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 people, while in Edge it was about 10,000.

All found extensions have already been removed from the Chrome Web Store. However, the Edge version, according to available data, remained available in the Microsoft store.

For those who had infected add-ons installed, I strongly recommend considering your data compromised and changing your passwords as soon as possible. Those who stored cryptocurrency in affected wallets should immediately transfer assets to new addresses.

How the malware works

After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. It then strips Content Security Policy (CSP) headers from visited sites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on crypto exchanges and other online services.

The modules can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Websites of Ledger and Trezor hardware wallets are spoofed with phishing pages to extract seed phrases.

The malicious code steals assets and account credentials from the largest exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet. Thus, virtually all popular methods of storing and exchanging cryptocurrency are under threat.

A separate function involves fake browser update notifications. Through them, the victim is pushed to perform actions needed by the attackers, thereby deepening the infection.

All of this works unnoticed by the user: externally, the add-on performs its stated task, while the theft happens in the background. This is why the danger went unnoticed for so long.

Other threats to cryptocurrency owners

In addition to extensions, other attack vectors have recently been recorded. Scammers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset owners.

In another case, hackers exploited an IT vulnerability in the "Screen Sharing" feature of Apple's macOS operating system. Through it, they gained unauthorized access to victims' computers.

Experts advise being careful about the browser extensions you install. Particular caution should be exercised with add-ons that request broad permissions.

Additionally, I recommend regularly checking the list of active extensions. This habit helps you notice a suspicious add-on in time and remove it before it causes damage.

Combining these measures reduces the risk of losing funds and credentials. However, only caution when installing any third-party add-ons can fully protect you.

My verdict: this campaign is a vivid example of how attackers exploit users' trust in official extension stores. Buying out legitimate plugins followed by injecting malicious code through updates is an alarming trend that requires stricter moderation from the industry and a conscious approach to digital hygiene from users. Do not install what you can do without, and keep your funds on hardware wallets with minimal permissions granted to the browser.