My analysis of the digital security market situation has revealed a troubling trend: analysts at the company Socket have discovered 18 malicious extensions for Google Chrome and one for Microsoft Edge that are actively draining cryptocurrency wallets and stealing user credentials. The combined audience of two versions of one such add-on reached 80,000 people, and Russian users were also among those at risk.
These extensions load a modular framework aimed at stealing cryptocurrency, passwords, and browser history. At the same time, they disguise themselves as useful tools, showing victims advertising bait. The first traces of their activity date back to 2024.
Why the extensions are dangerous for Russians
The add-ons transmit data and passwords that users enter on any websites to attackers, and also collect information from Facebook accounts (owned by Meta, recognized as an extremist organization in Russia) and LinkedIn (blocked in Russia), extracting browsing history. The threat is not limited to one country: anyone who installed the infected extension is affected, so Russians are at risk just like everyone else.
Socket specialists found that some of the discovered add-ons did not contain malicious code at the time they appeared in the Chrome Web Store. Five of the sixteen extensions were purchased by attackers from their original developers and infected through automatic updates. This means the modules expand: malicious functions are added as needed.
One such add-on — Enable Right Click & Copy — Smart Unlock + OCR — works in Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 people, while in Edge it was about 10,000.
All discovered extensions have already been removed from the Chrome Web Store. However, the Edge version, according to available data, remained available in the Microsoft store.
For those who had infected add-ons installed, specialists advise considering their data compromised and changing passwords as quickly as possible. Experts recommend that those who stored cryptocurrency in affected wallets transfer their assets to new addresses.
How the malicious program works
After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. It then removes Content Security Policy (CSP) headers from visited websites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on crypto exchanges and other online services.
The modules can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Websites for Ledger and Trezor hardware wallets are spoofed with phishing pages to extract seed phrases.
The malicious code steals assets and account data from the largest exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet. Thus, virtually all popular methods of storing and exchanging cryptocurrency are under threat.
A separate feature involves fake browser update notifications. Through them, the victim is pushed to perform actions needed by the attackers, thereby deepening the infection.
All of this works unnoticed by the user: outwardly, the extension performs its stated task, while the theft runs in the background. This is precisely why the danger went unnoticed for so long.
Other threats to cryptocurrency owners
Malwarebytes Labs recently warned of a new phishing scheme. Scammers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset owners.
In another case, hackers exploited an IT vulnerability in the "Screen Sharing" feature of Apple's macOS operating system. Through it, they gained unauthorized access to victims' computers.
Malwarebytes Labs experts advise being careful about the browser extensions you install. Particular caution should be exercised with add-ons that request broad permissions.
Additionally, specialists recommend regularly checking the list of active extensions. Such a habit helps to notice a suspicious add-on in time and remove it before it causes damage.
The combination of these measures reduces the risk of losing funds and credentials. However, only caution when installing any third-party add-ons can fully protect you.
My comment: This attack is a vivid example of the evolution of cyber threats: attackers no longer hack systems — they infiltrate trusted software distribution channels. For investors, this is a signal to reconsider their habits: minimize the number of extensions, use hardware wallets for large amounts, and never enter seed phrases in a browser. In the era of modular attacks, vigilance is not paranoia but a necessary part of risk management.