Cybersecurity researchers have uncovered a campaign involving 19 crypto-stealing malicious browser extensions.

Socket said that the above-mentioned extensions (18 for Google Chrome and one for Microsoft Edge) were published or weaponized over the past six months. The security firm claims that the operation may date back to February 2024.

In some cases, attackers created extensions that initially appeared legitimate. In others, they acquired existing extensions from their original developers before making them malicious. 


XRP Price Drops Sharply After Fed Chair’s Comments


Peter Brandt Reveals He Is Long Bitcoin

Of the 19 extensions identified by Socket, 14 were created by the threat actor, and five were purchased from legitimate authors.

“Enable Right Click & Copy — Smart Unlock + OCR” was the most dangerous extension. Socket said the Chrome version had about 70,000 users when its malicious functionality was introduced. Meanwhile, an Edge version had roughly 10,000 users.

You Might Also Like

Title news

The Chrome extension has since been removed from the Chrome Web Store, according to Socket. However, the Edge version was still active.

Socket researchers also found that the malware removes Content Security Policy protections from websites.

More malicious modules 

The firm has spotted a multi-chain cryptocurrency wallet drainer targeting EVM-compatible, Solana and Tron wallets. The malware can tamper with legitimate “Connect Wallet” and “Swap” buttons to redirect users into attacker-controlled transaction flows.

Other modules target hardware-wallet users by displaying convincing fake Ledger and Trezor recovery or update pages to trick victims into entering their seed phrases. 

The campaign also includes modules designed to harvest authenticated sessions and account information from cryptocurrency platforms including Binance, Coinbase, Kraken, OKX, MEXC, KuCoin and Bybit, as well as MetaMask.

See also  20% Ethereum Rally Boosts Bitmine (BMNR) by $2.2 Billion: Tom Lee Backs Ether as Vital Layer for AI

Additional modules target Facebook and LinkedIn accounts, steal browsing history and deploy ClickFix-style fake browser-update pages and so on. 

Socket advised users to regularly review installed browser extensions and remove suspicious ones. 


Source link

Author

Shin John
Shin JohnYtv Market News
Share-market news writer and analyst with deep experience covering equities, commodities, forex, and cryptocurrencies for readers in the USA, UK, Canada, and Australia. Ytv Market News delivers timely market updates, practical trading insights, and clear explanations of macro and company-level catalysts that move prices. Combines on-the-ground financial reporting with technical analysis, using concise charts and actionable ideas to help investors and traders make smarter decisions.