Chrome Web Store Extensions Exposed for Crypto Theft and Browser Data Leaks
A cybersecurity investigation has uncovered a campaign involving multiple malicious extensions for Google Chrome and Microsoft Edge that deployed a modular malware framework designed to extract cryptocurrency assets, browser data, and user credentials.
Overview of the Malicious Campaign
Researchers identified 16 distinct malicious components, each with unique functions, describing the system as “highly extensible” and capable of evolving over time. The operation, traced to the Chrome Web Store, was first detected by application security firm Socket, with evidence suggesting it may have been active since early 2024.
Key Findings from the Investigation
Initial analysis revealed that several extensions appeared legitimate upon publication, offering the advertised features without malicious code. However, five of these extensions were later compromised through automated updates, with malware injected after their original developers relinquished control.
Malware Capabilities and Activities
Once installed, the malware establishes an encrypted WebSocket connection to command-and-control (C2) servers, enabling a range of malicious activities. These include:
- Exploiting legitimate “Connect Wallet” and “Swap” buttons on blockchain platforms such as EVM, Solana, and Tron to drain user wallets.
- Redirecting users to counterfeit Ledger and Trezor websites designed to harvest seed phrases.
- Extracting session tokens, account data, and balances from cryptocurrency exchanges like Coinbase, Binance, Kraken, and MetaMask.
- Capturing login credentials and form entries across websites, alongside browser history and account information.
- Displaying deceptive “ClickFix” prompts that trick users into executing attacker-controlled commands.
Notable Example: “Enable Right Click & Copy Smart Unlock + OCR”
One notable example, “Enable Right Click & Copy Smart Unlock + OCR,” was available on both Chrome and Edge, with over 70,000 Chrome users and 10,000 Edge users at the time of its compromise. While Google removed the Chrome version from its marketplace, the Edge variant remained accessible at the time of Socket’s report.
Removal and Mitigation Efforts
Socket’s findings highlight the framework’s adaptability, with researchers warning that additional modules may have been deployed. At the time of the report, all compromised extensions had been removed from the Chrome Web Store, but the Edge version remained available. The firm published a comprehensive list of affected extension IDs and associated C2 domains to aid in mitigation efforts.
User Advisories and Security Recommendations
Users who had any of the malicious extensions installed are advised to assume their credentials have been exposed and to reset login details immediately. Cryptocurrency holders affected by the campaign are urged to monitor accounts for unauthorized activity, as attackers can exploit stolen credentials to access funds.
Security experts note that even with valid login information, only 37% of malicious actions are blocked by existing defenses, underscoring the need for heightened vigilance.
Ongoing Risks and Industry Response
The investigation underscores ongoing risks posed by third-party extensions, particularly those with broad user bases. Organizations and individuals are encouraged to review installed extensions regularly and verify their legitimacy through official app stores.
