Chrome Extensions Exposed as Crypto-Stealing Malware
Crypto-stealing malicious browser extensions have been uncovered by cybersecurity researchers at Socket. The campaign involved 19 such extensions, 18 of which were for Google Chrome and one for Microsoft Edge.
The operation may date back to February this year, with the extensions published or weaponized over the past six months.
Sixteen of these extensions were created by a single threat actor, while three others were purchased from legitimate authors. The most popular extension was 'Enable Right Click & Copy, Smart Unlock + OCR', which had around 70,000 users on Chrome and roughly 10,000 users on Edge before being removed.
The malware targets EVM-compatible wallets, Solana wallets, Tron wallets, hardware wallet users, and cryptocurrency platforms like Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. It can also steal browsing history, display fake browser-update pages, and deploy ClickFix-style phishing attempts.