Malicious Chrome Extensions Steal Crypto and User Data from Millions of Users
Researchers have discovered 18 malicious add-ons for Google Chrome and one for Microsoft Edge that can steal cryptocurrency, passwords, and other user data. These extensions, which were found in the official browser store, initially worked normally before being compromised by attackers who added malicious code through automatic updates.
The most concerning aspect is that some of these programs were acquired by attackers from previous developers, with at least five instances identified. One such extension, 'Enable Right Click & Copy, Smart Unlock + OCR', was installed by over 80,000 users.
Once infected, the extensions can interfere directly within the browser, replacing crypto wallet connection buttons or displaying fake Ledger and Trezor pages to attempt to steal seed phrases. Users of Binance, Bybit, OKX, Coinbase, MetaMask, and other crypto services are at risk.
The danger is relevant for Russian users as well, as these add-ons work within the browser itself and can intercept data regardless of which country a person accesses from. In addition to cryptocurrency, malware can collect entered passwords and browsing history.