
Cybersecurity researchers have uncovered a cryptocurrency theft campaign involving 19 malicious browser extensions targeting crypto users.
Socket said the extensions—18 for Google Chrome and one for Microsoft Edge—were published or weaponized during the past six months. The security firm said the operation may date back to February 2024.
In some cases, the attackers created extensions that initially appeared legitimate. In others, they purchased existing extensions from their original developers before turning them malicious. Of the 19 extensions identified by Socket, 14 were created by the threat actor and five were acquired from legitimate authors.
“Enable Right Click & Copy — Smart Unlock + OCR” was the most dangerous extension identified. Socket said its Chrome version had approximately 70,000 users when the malicious functionality was introduced, while the Microsoft Edge version had roughly 10,000 users.
According to Socket, the Chrome extension has since been removed from the Chrome Web Store. The Edge version, however, remained active.
Socket researchers also found that the malware disables Content Security Policy protections on websites, allowing the attackers to interfere with legitimate web content and user interactions.
The campaign includes a multi-chain cryptocurrency wallet drainer targeting EVM-compatible, Solana and Tron wallets. The malware can tamper with legitimate “Connect Wallet” and “Swap” buttons, redirecting users into transaction flows controlled by the attackers.
Other modules target hardware-wallet users by displaying convincing fake Ledger and Trezor recovery or update pages. These pages are designed to trick victims into entering their seed phrases.
The campaign also contains modules that harvest authenticated sessions and account information from cryptocurrency platforms, including Binance, Coinbase, Kraken, OKX, MEXC, KuCoin and Bybit, as well as MetaMask.
Additional modules target Facebook and LinkedIn accounts, steal browsing history and deploy ClickFix-style fake browser-update pages, among other capabilities.
Socket advised users to regularly review their installed browser extensions and remove any suspicious ones.
No Comments