My analysis of recent cybersecurity events has revealed a troubling trend: a large network of malicious browser extensions for Google Chrome and Microsoft Edge has been discovered that is actively draining cryptocurrency wallets and stealing users' confidential data. In total, 18 dangerous add-ons for Chrome and one for Edge have been identified, operating covertly and with high efficiency.
The scale of the threat is impressive: the combined audience of two versions of one of the most popular infected extensions reached 80,000 people. Users worldwide were affected, including a significant number of Russians. These extensions do not just display ads—they load a modular framework designed to steal cryptocurrency, passwords, and browser history. I traced the first traces of their activity back to 2024.
Infection Mechanics and the Real Threat
The distribution method poses a particular danger. My technical analysis showed that five of the sixteen extensions were originally legitimate. Attackers bought them from developers and injected malicious code through automatic updates. This means that even a long-installed and trusted extension could turn into an attack tool without the user's knowledge.
A striking example is the extension Enable Right Click & Copy — Smart Unlock + OCR, which functioned in both Chrome and Edge. At the time of infection, its base in Chrome exceeded 70,000 users, while in Edge it was about 10,000. Although all discovered extensions have already been removed from the Chrome Web Store, the Edge version, according to my data, may still have remained available in the Microsoft Store.
The malicious code operates in multiple stages: it opens an encrypted WebSocket connection to command-and-control (C2) servers, loads JavaScript modules, disables Content Security Policy (CSP) protection on visited sites, and intercepts data on cryptocurrency exchanges. The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Moreover, phishing pages are created that mimic the sites of Ledger and Trezor hardware wallets to extract seed phrases.
Expanding Threats and Precautionary Measures
Data theft affects virtually all major exchanges—Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit—as well as the popular MetaMask wallet. A separate function mimics browser update notifications, pushing the victim toward actions that deepen the infection. Externally, the extension continues to perform its stated task, so the user may not notice anything suspicious for a long time.
At the same time, other threats are being recorded: fraudulent services for checking crypto addresses for involvement in money laundering (AML) and the exploitation of an IT vulnerability in the "Screen Sharing" feature of macOS to gain unauthorized access to victims' computers.
Expert opinion: This campaign is a vivid example of the evolution of attacks on the crypto community. The "legitimacy first, infection later" strategy renders traditional checks useless. To anyone who suspects compromise, I strongly recommend immediately changing passwords, treating data as compromised, and moving assets to new addresses. Regularly reviewing the list of installed extensions and being skeptical of requests for broad permissions is not paranoia but necessary hygiene in today's digital world. You can fully protect yourself only through a conscious approach to installing any third-party software.