Malware Tainted Browser Extensions Drain Crypto, Harvest Sensitive Data
Security researchers have identified malware in 19 Chrome and Edge browser extensions that targeted digital wallets and collected sensitive data. The affected tools, which include Enable Right Click & Copy, RapidLens, QuickLens, Private Crypto News Reader, and DeFi Pulse Tracker, were designed to drain cryptocurrency from Solana, Tron, and EVM wallets.
Five of the extensions were legitimate products that were compromised by attackers who bought them and added malware. The remaining 14 were built by the attackers themselves, with a malicious update installed after users had downloaded them.
According to Socket, a software security firm that monitors open-source code and browser add-ons for hidden malware, the affected extensions pulled data from Facebook and LinkedIn, as well as browser history and login details. Google has since removed the Chrome listings for these extensions.