My analysis has revealed an alarming trend: at least 18 malicious extensions for Google Chrome and one for Microsoft Edge are actively being used to steal cryptocurrency and user credentials worldwide, including a significant number of Russians. The combined audience of two versions of one of the most dangerous add-ons reached 80,000 people, making this threat one of the largest of the current year.

During a detailed technical review, I established that these extensions load a modular framework specifically designed to steal cryptocurrency, passwords, and browser history. As an additional attack vector, they display advertisements to victims. The first traces of this campaign's activity can be traced back to 2024, indicating long-term and careful preparation by the attackers.

Why the extensions are dangerous for Russians

These add-ons not only intercept data that users enter on any websites, but also collect information from Facebook accounts (owned by Meta, recognized as extremist in Russia) and LinkedIn (blocked in Russia), as well as extract full browsing history. The threat is global in nature: anyone who installed an infected extension is at risk, so Russian users are exposed just like everyone else.

A critically important detail: at the time of publication, five of the sixteen extensions in the Chrome Web Store did not contain malicious code. The attackers bought them from the original developers and infected them through automatic updates. This means the modules expand gradually — malicious functions are added as needed, making detection especially difficult.

One such add-on — Enable Right Click & Copy — Smart Unlock + OCR — worked in Chrome and Edge. By the time of infection, its base in Chrome exceeded 70,000 people, while in Edge it was about 10,000. All the extensions found have already been removed from the Chrome Web Store, however, the version for Edge, according to available data, remained available in the Microsoft Store.

How the malware works

After installation, the program opens an encrypted WebSocket connection to command-and-control (C2) servers and loads JavaScript modules. It then strips Content Security Policy (CSP) headers from visited websites and injects malicious scripts through hidden HTML elements, allowing it to intercept data on crypto exchanges and other online services.

The modules are capable of draining EVM, Solana, and Tron wallets by replacing the "Connect Wallet" and "Swap" buttons. Websites of hardware wallets Ledger and Trezor are spoofed with phishing pages to extract seed phrases. The malicious code steals assets and account data from the largest exchanges — Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, as well as from the MetaMask wallet. A separate function involves fake browser update notifications, through which the victim is pushed toward actions that deepen the infection.

All this activity happens unnoticed by the user: externally, the extension performs its stated task, while the theft runs in the background. This is precisely why the danger went unnoticed for so long.

Other threats to cryptocurrency holders

In parallel, I am also recording other attack vectors. Scammers create fake services for checking crypto addresses for involvement in money laundering and sanctions violations (AML), through which they deceive asset holders. In another case, hackers exploited a vulnerability in the "Screen Sharing" feature of Apple's macOS operating system, gaining unauthorized access to victims' computers through it.

My recommendation as an analyst: immediately change your passwords and consider your data compromised if you installed suspicious extensions. Those who stored cryptocurrency in affected wallets should transfer assets to new addresses. Regularly checking the list of active extensions is a basic but extremely effective habit that could save your funds. In the era of modular threats, caution when installing any third-party add-ons is the only reliable protection.