My analysis of recent cybersecurity incident data has revealed a troubling trend: attackers are actively using malicious browser extensions to drain cryptocurrency wallets and steal sensitive data. During an independent investigation conducted with the participation of code protection experts, 18 dangerous add-ons for Google Chrome and one for Microsoft Edge were discovered. The combined audience of these extensions reached 80,000 users, and Russian holders of digital assets were also among those at risk.
Attack Mechanics: A Hidden Threat in Familiar Tools
These extensions load a modular framework aimed at stealing cryptocurrency, passwords, and browser history. They also display advertising banners to victims, masking their destructive activity. The first traces of this campaign date back to 2024, indicating a long-running and carefully planned operation.
Particularly dangerous is the fact that some of the extensions did not contain malicious code at the time of publication in the Chrome Web Store. Five of the sixteen add-ons were purchased from legitimate developers and infected through automatic updates. This means that malicious functions were added gradually, as needed, making their detection extremely difficult.
One such extension, "Enable Right Click & Copy — Smart Unlock + OCR," operated in Chrome and Edge. By the time of infection, its user base in Chrome exceeded 70,000, while in Edge it was about 10,000. All detected extensions have already been removed from the Chrome Web Store, but the Edge version, according to available data, remained available in the Microsoft Store.
Technical Details and Scope of Damage
After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. It strips Content Security Policy (CSP) headers from visited sites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on cryptocurrency exchanges and other online services. The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Fake versions of Ledger and Trezor hardware wallet sites are created to extract seed phrases.
The malicious code steals assets and account data from major exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet. Virtually all popular methods of storing and exchanging cryptocurrency are under threat. A separate feature involves fake browser update notifications, through which victims are pushed toward actions that deepen the infection.
Other Threats and Recommendations
In addition to extensions, experts warn of a new phishing scheme involving fake services that check crypto addresses for involvement in money laundering (AML). Exploitation of a vulnerability in the macOS "Screen Sharing" feature was also identified, through which hackers gained unauthorized access to victims' computers.
Affected users are strongly advised to consider their data compromised and immediately change their passwords. Those who stored cryptocurrency in affected wallets should transfer assets to new addresses.
My comment: This attack is yet another reminder that even "harmless" extensions can become a Trojan horse. Regularly reviewing the list of installed add-ons and being wary of requests for broad permissions is not paranoia but necessary hygiene for anyone working with digital assets. In the world of DeFi, security begins with basic caution.