A large-scale campaign to steal crypto assets through browser extensions has been uncovered during an independent investigation. It involves 18 malicious add-ons for Google Chrome and one for Microsoft Edge, which not only drain wallets but also steal credentials. The combined audience of two versions of one of the extensions exceeded 80,000 people, and users from Russia were also among those affected.

This is not just another phishing scheme, but a well-thought-out multi-stage attack. The malicious extensions load a modular framework aimed at stealing cryptocurrency, passwords, and browser history. At the same time, victims are shown advertising "bait" to hide the true activity. The first traces of this activity date back to 2024, indicating the long-term and systemic nature of the threat.

Why extensions are dangerous for Russians

The add-ons transmit data and passwords that users enter on any websites to attackers, and also collect information from Facebook accounts (owned by Meta, recognized as an extremist organization in Russia) and LinkedIn (blocked in the Russian Federation), extracting browsing history. The danger is not limited to one country — anyone who installs an infected extension is at risk, so Russians are exposed just like everyone else.

A key feature of the discovered add-ons is their cunning. Some of them did not contain malicious code at the time they appeared in the Chrome Web Store. Five of the sixteen extensions were purchased by attackers from their original developers and infected through automatic updates. This means the modules expand: malicious functions are added as needed, bypassing standard security checks.

One such extension — Enable Right Click & Copy - Smart Unlock + OCR — worked in Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 people, and in Edge it was about 10,000. All found extensions have already been removed from the Chrome Web Store, but the Edge version, according to available data, remained available in the Microsoft Store.

For those who had infected add-ons installed, experts strongly recommend considering their data compromised and changing passwords as soon as possible. Those who stored cryptocurrency in affected wallets are advised by experts to transfer assets to new addresses.

How the malware works

After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. It then removes Content Security Policy (CSP) headers from visited sites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on crypto exchanges and other online services.

The modules can drain EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Websites of hardware wallet providers Ledger and Trezor are spoofed with phishing pages to extract seed phrases. The malicious code steals assets and account data from the largest exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit — as well as from the MetaMask wallet. Virtually all popular methods of storing and exchanging cryptocurrency are at risk.

A separate feature is fake browser update notifications. Through them, the victim is pushed to perform actions needed by the attackers, thereby deepening the infection. All of this works unnoticed by the user: externally, the extension performs its stated task, while the theft happens in the background. This is precisely why the danger went unnoticed for so long.

Other threats to cryptocurrency holders

In parallel, Malwarebytes Labs specialists warned of a new phishing scheme. Scammers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset holders. In another case, hackers exploited an IT vulnerability in the "Screen Sharing" feature of Apple's macOS operating system, gaining unauthorized access to victims' computers through it.

Experts advise being careful about the browser extensions you install. Particular caution should be exercised with add-ons that request broad permissions. Additionally, it is recommended to regularly check the list of active extensions — such a habit helps to notice a suspicious add-on in time and remove it before it causes damage.

The combination of these measures reduces the risk of losing funds and credentials. However, only caution when installing any third-party add-ons can fully protect you.

My analysis: This attack is a vivid example of the evolution of cyber threats: attackers no longer hack defenses, they attack user trust through legitimate distribution channels. Buying out extensions and then infecting them through updates is an alarming trend that calls into question the very security model of browser stores. Users should reconsider their habits: minimize the number of extensions and regularly audit their access rights.