**Massive Browser Extension Campaign Targeting Cryptocurrency Wallets Uncovered**
A large-scale campaign utilizing malicious browser extensions has been identified, targeting users of the Google Chrome and Microsoft Edge web browsers. Cybersecurity investigators have uncovered a cluster of 18 Google Chrome extensions and one Microsoft Edge extension that were specifically designed to steal wallet secrets and drain cryptocurrency from unsuspecting users.
While the malicious versions were published over the last six months, evidence suggests that this operation has been running continuously since February 2024, making it a persistent and evolving threat.
**The Deceptive Strategy**
The attackers employed a highly effective delivery method to compromise users. Initially, the threat actor either purchased legitimate browser extensions from their original creators or pushed completely clean versions of their own software. These initial versions functioned exactly as advertised, gathering downloads and building a user base without raising any red flags.
Once a sufficient number of users had installed the extensions, the attackers released a new update that silently infused the software with malicious capabilities. This technique is particularly insidious because modern browsers often update extensions automatically in the background. When the new, compromised version is pushed out, users are unaware that the safety of their data has been compromised.
**Scope and Targets**
Of the 19 extensions identified, 14 were built from scratch by the threat actor, while five were acquired from previous owners. The malicious add-ons were disguised as legitimate productivity tools, including SEO analyzers, image search assistants, crypto trackers, and PDF protection utilities.
The extension with the most significant impact is a tool claiming to enable right-click copying and smart unlocking with OCR technology, which has amassed a combined install base of roughly 80,000 users across both Chrome and Edge browsers.
**Technical Mechanics and Data Theft**
Once installed, the malicious extensions bypass standard web protections by stripping Content Security Policy (CSP) headers from every webpage the user visits. This allows the software to inject arbitrary JavaScript modules directly into the user’s browsing sessions. In total, sixteen distinct malicious modules have been identified within the campaign.
The extensions establish persistent WebSocket connections to command-and-control (C2) servers, allowing the attackers to send remote commands and receive stolen data. The infrastructure is designed to rotate its C2 endpoints based on instructions received from the initial server, making it difficult for security teams to track and block the traffic. This dynamic routing also enables the attackers to funnel victims to different dedicated infrastructure, reducing the risk of detection.
The modules deployed by the extensions span a wide range of data theft activities, including:
* Multi-chain cryptocurrency wallet drainers
* Hardware wallet seed-phrase harvesters
* Cryptocurrency exchange and general wallet account stealers
* Universal credential and form grabbers
* Targeted stealers for Facebook and LinkedIn accounts
* Browser history scrapers
* ClickFix-style lures designed to trick users into copying and pasting malicious commands
**The Unknown Threat Actor**
The identity of the individuals or group orchestrating this campaign remains unknown. However, the fact that they have been successfully operating for over two years points to a highly capable and organized threat actor with significant resources and technical expertise.
***
**Frequently Asked Questions (FAQ)**
**Q: How do these malicious browser extensions get installed?**
A: Users typically install them willingly from the Chrome Web Store or Edge Add-ons marketplace, believing they are legitimate tools. The attackers compromise the extensions by publishing malicious updates to already-trusted software, which are then automatically installed by the browser’s default update settings.
**Q: What kind of data do these extensions steal?**
A: The extensions are designed to steal a wide variety of sensitive information, primarily focusing on cryptocurrency wallet seed phrases and private keys. They also harvest login credentials for crypto exchanges, social media accounts like Facebook and LinkedIn, browser history, and general form data.
**Q: Can these extensions affect users who do not use cryptocurrency?**
A: Yes. While the primary goal is crypto theft, the extensions also include universal credential grabbers and social media stealers. Additionally, because they can execute arbitrary code on any website a user visits, they pose a general privacy and security risk to all users, regardless of whether they hold digital assets.
**Q: How can users protect themselves from malicious browser extensions?**
A: Users should regularly audit their installed extensions and remove any they no longer use. It is important to carefully review the permissions requested by an extension before installing it and to verify the developer’s legitimacy. Disabling automatic extension updates and manually reviewing update notes before accepting them can also help catch malicious payloads.
***
**Conclusion**
The discovery of this widespread browser extension campaign serves as a stark reminder of the vulnerabilities that exist within the browser ecosystem. By exploiting the trust users place in legitimate productivity and crypto-tracking tools, attackers can bypass traditional security measures and compromise sensitive digital assets with little resistance. Maintaining vigilance, practicing careful extension management, and approaching unsolicited browser updates with skepticism are essential steps for users looking to protect their personal data and digital finances in an increasingly connected web environment.
Thank you for reading



