My team and I conducted an in-depth analysis of a new wave of cyber threats targeting digital asset holders. During an independent investigation, we discovered 18 malicious extensions for Google Chrome and one for Microsoft Edge. These seemingly harmless add-ons not only display ad clutter but also silently drain cryptocurrency wallets and steal credentials in the background. The combined audience of two versions of one of the most popular extensions reached 80,000 users, with a significant portion located in Russia.

Infection mechanics and the hidden threat

What is particularly alarming is the method of spreading the malicious code. We found that five of the sixteen extensions were originally legitimate. Attackers purchased them from developers and injected malicious modules through automatic updates. This means that a user who installed an extension a month ago could have been compromised only after it "updated" to an infected version. A striking example is the extension "Enable Right Click & Copy — Smart Unlock + OCR," whose user base exceeded 70,000 in Chrome and about 10,000 in Edge.

After installation, the program establishes an encrypted connection to a command-and-control (C2) server and downloads JavaScript modules. It removes Content Security Policy (CSP) protection from websites and injects hidden HTML elements to intercept data. The modules are designed to drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Furthermore, phishing pages mimicking Ledger and Trezor are created to extract seed phrases.

The malicious code can steal data from major exchanges, including Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, as well as from MetaMask. A separate feature involves fake browser update notifications that trick the victim into performing actions that deepen the infection. Externally, the extension continues to perform its stated function, so the user does not notice anything suspicious for a long time.

Analyst recommendations and conclusions

All discovered extensions have already been removed from the Chrome Web Store, but the Edge version, according to our data, remained available in the Microsoft Store. I strongly recommend that anyone who installed such add-ons immediately change their passwords, treat their data as compromised, and transfer crypto assets to new addresses. It is also worth paying attention to other threats, such as fake AML services and vulnerabilities in macOS.

My verdict: this attack is yet another reminder that even time-tested extensions can become a Trojan horse. Regularly reviewing the list of installed add-ons and being cautious about granting them broad permissions is the only reliable way to protect yourself in today's digital world.