Crypto-Stealing Browser Extensions Uncovered in Large-Scale Campaign
Cybersecurity researchers have uncovered a campaign involving malicious browser extensions that steal crypto wallets. The threat actor has been active for at least six months, and some of these extensions initially appeared legitimate before being weaponized.
The operation, which may date back to February 2024, involved the creation or acquisition of 19 extensions for Google Chrome and Microsoft Edge. Out of these, 14 were created by the threat actor, while five were purchased from their original developers.
The most damaging extension was 'Enable Right Click & Copy, Smart Unlock + OCR', which had around 70,000 users on Chrome when its malicious functionality was introduced. The edge version had roughly 10,000 users and remained active even after the Chrome extension was removed from the Chrome Web Store.