Chrome and Edge extensions used to steal crypto from wallets, exchanges, and browser data
Socket says a cluster of browser extensions that started out clean in Chrome Web Store later turned malicious after being bought from the original developers and pushed with automatic updates. For high-risk PSPs and crypto platforms, the useful part is simple: browser extensions can become a delivery layer for wallet theft, credential theft, and session hijacking without looking suspicious at install time.
- Socket identified 16 extensions involved. Five of them were originally legitimate, then were purchased and infected through automatically distributed updates. In other words, the payload arrived later, after the extension had already built up trust and users.
- Researchers believe the campaign began in 2024. One example, Enable Right Click & Copy — Smart Unlock + OCR, was available for Chrome and Edge. By the time it turned malicious, Socket counted more than 70,000 users in Chrome and about 10,000 in Edge.
- Once installed, the malware opened an encrypted WebSocket connection to command-and-control (C2) servers, loaded JavaScript modules, removed Content Security Policy (CSP) headers from every site visited, and injected malicious scripts through hidden HTML elements. That is the sort of plumbing that lets attackers sit inside a user session rather than just waiting for a password leak.
- Socket says the modules can drain EVM, Solana, and Tron wallets by swapping out “Connect Wallet” and “Swap” buttons, and can replace Ledger and Trezor hardware-wallet sites with phishing pages to steal seed phrases. The same tooling was also used to steal crypto assets and account data from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask.
- The extensions also captured passwords and data entered on any website, pulled information from Facebook and LinkedIn accounts, and extracted browser history. They even showed fake browser update prompts designed to get victims to run commands chosen by the attackers. As of now, none of the malicious extensions remain in Chrome Web Store, but Edge users are still being told to check their installed add-ons.
Separately, Malwarebytes Labs recently warned about phishing sites that impersonate crypto address screening tools for AML and international sanctions checks, and attackers have also abused a macOS Screen Sharing vulnerability to gain unauthorized access to computers. Different entry point, same basic problem: once the user trusts the surface, the payment or wallet layer is next.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!