Malicious Browser Extensions Steal Crypto Wallets in Widespread Campaign
Cybersecurity researchers have uncovered a campaign involving 19 malicious browser extensions designed to steal crypto wallets.
The threat actor, identified as Socket, published or weaponized 18 Google Chrome and one Microsoft Edge extension over the past six months. The operation may date back to February 2024.
Sometimes, attackers created extensions that initially appeared legitimate, while in other cases they acquired existing extensions from their original developers before making them malicious.
The most dangerous extension was 'Enable Right Click & Copy, Smart Unlock + OCR', which had about 70,000 users when its malicious functionality was introduced. The Chrome version has since been removed from the Chrome Web Store, but the Edge version remained active with roughly 10,000 users.