Malicious Browser Extensions Hijack Crypto Wallets and Steal User Data

Security researchers at Socket uncover a malware campaign spread through browser extensions on the Chrome Web Store and Microsoft Edge add-ons marketplace. The malicious framework deploys up to 19 distinct modules that steal cryptocurrency, sensitive data, and browser history, and may have been active since early 2024. Researchers describe the framework as highly extensible, warning that new payloads are likely to emerge as the operation evolves.

Many of the extensions initially provided their advertised functionality and contained no malware. According to Socket, five of the extensions were acquired from their original creators and later injected with malicious code through automatic updates. One example, "Enable Right Click Copy Smart Unlock + OCR," turned malicious while installed by at least 70,000 Chrome users and 10,000 Edge users. Google removed the extension quickly, but the Edge version remains available at the time of the report.

Once installed, the malware connects to command-and-control servers, strips Content Security Policy headers from visited websites, and injects malicious scripts through hidden HTML elements. Its capabilities include draining EVM, Solana, and Tron wallets by hijacking Connect Wallet buttons, replacing Ledger and Trezor sites with seed-phrase phishing pages, stealing sessions and balances from major exchanges like Coinbase and Binance, harvesting Facebook and LinkedIn data, and displaying fake ClickFix browser updates that trick victims into running attacker commands.

Read More at the original source →