A large-scale campaign to steal digital assets and confidential data has been uncovered in browser extension stores. During my in-depth analysis of the ecosystem of add-ons for Google Chrome and Microsoft Edge, 18 malicious modules for Chrome and one for Edge were found, operating on the principle of "drainers"—programs that empty victims' cryptocurrency wallets.

The combined audience of two versions of one of the most active extensions reached 80,000 users, and a significant portion of them are Russian-speaking. Everyone who installed the infected software was at risk, regardless of geographic location.

Attack Mechanics and Hidden Threat

The attackers' tactics are particularly alarming. Five of the sixteen extensions were legitimate at the time of publication in the Chrome Web Store. Cybercriminals bought them from original developers and injected malicious code through automatic updates, as happened with the extension Enable Right Click & Copy — Smart Unlock + OCR, whose base in Chrome exceeded 70,000 installations and in Edge about 10,000. The first traces of such activity date back to 2024.

After installation, the program establishes an encrypted WebSocket connection to command servers and downloads JavaScript modules. It disables Content Security Policy protection on websites and intercepts data entered on crypto exchanges and online services. The modules can replace the "Connect Wallet" and "Exchange" buttons, as well as imitate pages of Ledger and Trezor hardware wallets to extract seed phrases.

Key platforms have been affected: Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. Externally, the extension continues to perform its stated functions, masking the background data theft.

Expert Assessment and Recommendations

Anyone who suspects they may be infected should immediately change their passwords and treat their data as compromised. Crypto assets should be moved to new addresses. Regularly checking the list of installed extensions and being wary of requests for broad permissions are basic but critically important measures.

Other threats are also being recorded in parallel: fake AML services for checking addresses and exploitation of a vulnerability in macOS Screen Sharing. In current conditions, security is not just caution but comprehensive hygiene. The market is moving toward self-service, and every user becomes their own bank and guardian. Only a combination of technical measures and behavioral vigilance can reduce risks to an acceptable level.