Skip to content
Back to Guavy Wire
Crypto

Chrome Extensions Exposed as Crypto-Stealing Malware

Instruments
BNB SOL
Share

Crypto-stealing malicious browser extensions have been uncovered by cybersecurity researchers at Socket. The campaign involved 19 such extensions, 18 of which were for Google Chrome and one for Microsoft Edge.

The operation may date back to February this year, with the extensions published or weaponized over the past six months.

Sixteen of these extensions were created by a single threat actor, while three others were purchased from legitimate authors. The most popular extension was 'Enable Right Click & Copy, Smart Unlock + OCR', which had around 70,000 users on Chrome and roughly 10,000 users on Edge before being removed.

The malware targets EVM-compatible wallets, Solana wallets, Tron wallets, hardware wallet users, and cryptocurrency platforms like Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. It can also steal browsing history, display fake browser-update pages, and deploy ClickFix-style phishing attempts.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc