Researchers have uncovered malicious browser extensions for Chrome and Edge that stole cryptocurrency, browsing data and account information from victims.
Malicious browser extensions targeted Chrome and Edge users
Application-security firm Socket discovered a malware framework hidden in browser extensions that appeared legitimate when first published.
The operation may have been active since early 2024. Researchers found 19 modules with different capabilities, which allowed attackers to expand the malware over time.
According to Socket, attackers acquired at least five legitimate extensions from their original developers. They then added malicious code through automatic extension updates.
Extensions injected scripts into websites
After installation, the malware connected to command-and-control servers through encrypted WebSocket connections.
It then downloaded JavaScript modules and removed Content Security Policy protections from sites the victim visited. The extensions could also inject malicious scripts into web pages through hidden elements.
This gave attackers the ability to monitor browser activity and interfere with trusted websites.
Campaign targeted crypto wallets and exchanges
The malicious browser extensions could hijack legitimate wallet-connect and token-swap buttons to drain EVM, Solana and Tron wallets.
Researchers also found phishing modules that could imitate Ledger and Trezor websites to steal recovery phrases.
Other modules targeted cryptocurrency exchanges and wallet services. They could steal sessions, account data, tokens and balances from services including Coinbase, Binance, Kraken, OKX, MetaMask and others.
The malware could also collect browser history, record form entries and credentials, and harvest Facebook or LinkedIn account information.
Google removed affected Chrome extensions
One affected extension, Enable Right Click & Copy — Smart Unlock + OCR, had at least 70,000 Chrome users and 10,000 Edge users before it turned malicious.
Google removed the extension from the Chrome Web Store. At the time Socket published its report, the Edge version was still available.
None of the identified malicious browser extensions remained available through the Chrome Web Store at the time of publication.
Users should secure affected accounts
Anyone who installed one of the extensions should remove it immediately and change passwords for accounts used in that browser.
Users should also review active sessions and enable multi-factor authentication where available.
Crypto holders who may have interacted with the affected extensions should move their funds to a newly created wallet. They should never enter a wallet recovery phrase into a website or browser pop-up.


0 responses to “Malicious Browser Extensions Stole Crypto and Sensitive Data”