Malicious Chrome Extensions Swindle Tens of Thousands
Researchers at Socket Inc. have uncovered a malicious campaign that used Chrome's extension system to steal cryptocurrency from tens of thousands of users.
The campaign, which affected about 80,000 people, involved 19 malicious extensions aimed at Chrome and Edge users.
Many of the extensions appeared to work normally for months before attackers added malicious code. The extensions have since been removed from both browser stores, but users may still be affected if they have not manually removed the add-ons.
The malicious extensions used a similar strategy, with 14 developed directly by the cybercriminals and five purchased from legitimate developers and companies.