Cybersecurity researchers have uncovered a campaign involving 19 crypto-stealing malicious browser extensions.
Socket said that the above-mentioned extensions (18 for Google Chrome and one for Microsoft Edge) were published or weaponized over the past six months. The security firm claims that the operation may date back to February 2024.
In some cases, attackers created extensions that initially appeared legitimate. In others, they acquired existing extensions from their original developers before making them malicious.
Of the 19 extensions identified by Socket, 14 were created by the threat actor, and five were purchased from legitimate authors.
"Enable Right Click & Copy — Smart Unlock + OCR" was the most dangerous extension. Socket said the Chrome version had about 70,000 users when its malicious functionality was introduced. Meanwhile, an Edge version had roughly 10,000 users.
The Chrome extension has since been removed from the Chrome Web Store, according to Socket. However, the Edge version was still active.
Socket researchers also found that the malware removes Content Security Policy protections from websites.
More malicious modules
The firm has spotted a multi-chain cryptocurrency wallet drainer targeting EVM-compatible, Solana and Tron wallets. The malware can tamper with legitimate "Connect Wallet" and "Swap" buttons to redirect users into attacker-controlled transaction flows.
Other modules target hardware-wallet users by displaying convincing fake Ledger and Trezor recovery or update pages to trick victims into entering their seed phrases.
The campaign also includes modules designed to harvest authenticated sessions and account information from cryptocurrency platforms including Binance, Coinbase, Kraken, OKX, MEXC, KuCoin and Bybit, as well as MetaMask.
Additional modules target Facebook and LinkedIn accounts, steal browsing history and deploy ClickFix-style fake browser-update pages and so on.
Socket advised users to regularly review installed browser extensions and remove suspicious ones.
u.today