Crypto-Theft via Trusted-Looking Extensions: 19 Chrome/Edge Add-Ins Harbor Hidden Malware

Security researchers uncovered 19 Chrome/Edge extensions that mask legitimate functionality while stealing wallet data and draining crypto. The campaign, tracked as Superior by Socket, updates compromised extensions with malicious code after initial benign versions, establishing C2 channels via WebSocket, rotating endpoints, and per‑victim exfiltration. The extensions strip CSP headers to inject 16 malicious modules—ranging from seed-phrase harvesters to credential grabbers—enabling broad data theft. One lead extension, 'Enable Right Click & Copy — Smart Unlock + OCR,' has about 80,000 installs. The attackers reportedly acquired some legitimate extensions or bought them; the operation has been ongoing since February 2024, with broader scope than previously believed. Attribution remains unknown.
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code The Hacker News
- Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Bitdefender
- Chrome Extension Malware Campaign Hits 19 Browser Add-Ons Coin Gabbar
- 40 Fake Firefox Crypto Wallet Extensions Exposed Stealing Users’ Secrets and Credentials Yahoo Tech
- Malicious Browser Extensions Stealing Crypto Wallet Data: What Users Need To Know Bitcoin World
Reading Insights
1
10
3 min
vs 4 min read
87%
800 → 107 words
Want the full story? Read the original article
Read on The Hacker News