Browser Extensions Used to Steal Crypto Wallets in Sophisticated Malware Campaign
Cybersecurity researchers have discovered a malicious campaign involving 19 browser extensions that steal cryptocurrency wallets. The operation, which may date back to February 2024, involved 18 Google Chrome extensions and one Microsoft Edge extension.
The security firm Socket said the attackers created or acquired existing extensions from their original developers before making them malicious. In some cases, the attackers made legitimate-looking extensions, while in others they purchased extensions from legitimate authors.
The most dangerous extension was 'Enable Right Click & Copy, Smart Unlock + OCR', which had around 70,000 users when its malicious functionality was introduced. The Edge version of this extension had roughly 10,000 users and was still active even after the Chrome version was removed from the Chrome Web Store.
The malware targets various types of cryptocurrency wallets, including those on EVM-compatible, Solana, and Tron chains. It can tamper with legitimate 'Connect Wallet' and 'Swap' buttons to redirect users into attacker-controlled transaction flows. Other modules target hardware-wallet users by displaying convincing fake Ledger and Trezor recovery or update pages.
The campaign also includes modules designed to harvest authenticated sessions and account information from cryptocurrency platforms, including Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. Socket advised users to regularly review installed browser extensions and remove suspicious ones.