19 Browser Extensions Caught Stealing Crypto Wallets and Passwords
Nineteen browser extensions have been linked to a malware operation that steals cryptocurrency wallet secrets, passwords and other data. The extensions appeared to offer useful tools, including search helpers, price monitors and copy-unlocking features, before later updates quietly introduced the harmful code.
The campaign affects 18 Chrome extensions and one Microsoft Edge extension. Attackers acquired established add-ons with existing users, then used routine automatic updates to deliver harmful new versions. The most exposed pair potentially reached 80,000 users.
Researchers at Socket.dev identified the operation and said the related extensions share a flexible framework for downloading and running fresh payloads. The campaign mainly pursues wallet theft and cryptocurrency draining, but can also collect credentials, session data and browsing history.