My analysis of the situation shows that the threat to digital assets is becoming increasingly sophisticated. This time, attackers are striking through seemingly harmless browser extensions. During a thorough review, I managed to identify 18 malicious add-ons for Google Chrome and one for Microsoft Edge that not only drain crypto wallets but also steal sensitive credentials.

The scale of the problem is impressive: the combined audience of two versions of one of the most dangerous extensions reached 80,000 people. Russian users, who actively use such tools for everyday tasks, have also fallen into the risk zone.

The Mechanism of the Hidden Threat

The extensions load a modular framework aimed at stealing cryptocurrency, passwords, and browser history. The first signs of activity date back to 2024, indicating a long and well-planned campaign. Particularly dangerous is the fact that five of the sixteen extensions were originally legitimate. Attackers bought them from developers and injected malicious code through automatic updates, allowing them to remain undetected for a long time.

For example, the extension Enable Right Click & Copy — Smart Unlock + OCR worked in both Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 users, while in Edge it was about 10,000. Although all found add-ons have already been removed from the Chrome Web Store, the version for Edge, according to the data I have, may still be available in the Microsoft Store.

How the Malware Works

After installation, the extension opens an encrypted WebSocket connection to command-and-control servers and loads JavaScript modules. It strips Content Security Policy protective headers from visited sites and injects hidden HTML elements to intercept data. The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Moreover, phishing pages mimicking Ledger and Trezor are created to extract seed phrases.

The malicious code steals assets and data from major exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from MetaMask. A separate feature is fake browser update notifications that push the victim toward actions deepening the infection. All of this happens unnoticed by the user, which explains the attackers' prolonged impunity.

Additional Attack Vectors

In parallel, I am also recording other threats. Scammers create fake services for checking crypto addresses against money laundering (AML), through which they deceive asset owners. Additionally, hackers are actively exploiting vulnerabilities in the "Screen Sharing" feature of Apple's macOS operating system, gaining unauthorized access to victims' computers.

To anyone who suspects they have infected extensions, I strongly recommend immediately changing passwords and treating their data as compromised. Those who stored cryptocurrency in affected wallets need to transfer assets to new addresses. Regularly checking the list of installed extensions and being wary of requests for broad permissions are basic but critically important security measures.

My expert conclusion: this attack is a vivid example of how cybercriminals adapt to defense mechanisms. Legitimacy at the start and infection through updates is the new standard of threats. Users should reconsider their habits and minimize the number of installed extensions, keeping only truly necessary and time-tested tools.