Home / Companies / Socket / Blog / Post Details
Content Deep Dive

19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads

Blog post from Socket

Post Details
Company
Date Published
Author
Karlo Zanki
Word Count
3,007
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket researchers identified a “Superior” malware campaign involving 18 Chrome extensions and one Edge extension that initially appeared legitimate before later updates introduced modular payloads for cryptocurrency theft, credential harvesting, browsing-history exfiltration, social-media account abuse, and fake-update phishing. Some extensions were created by the attackers, while five were reportedly acquired from legitimate developers, including a right-click utility with an estimated 70,000 Chrome users and a related Edge version with roughly 10,000 users, illustrating how automatic extension updates can expand exposure. The extensions establish encrypted WebSocket connections to command-and-control servers, remove websites’ Content Security Policy protections, and dynamically inject malicious JavaScript into visited pages through hidden elements and event handlers. Observed modules target cryptocurrency wallets and exchanges, impersonate Ledger and Trezor recovery workflows to steal seed phrases, collect form inputs and session tokens, and display deceptive browser-update prompts that can encourage users to run attacker-provided commands. Socket linked the operation to techniques reported as early as February 2024 and warned that its rotating infrastructure, dynamically delivered payloads, and use of purchased extensions make it resilient and adaptable; it recommends that users regularly review and remove unnecessary or suspicious browser extensions.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.