19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads
Blog post from Socket
Socket researchers identified a “Superior” malware campaign involving 18 Chrome extensions and one Edge extension that initially appeared legitimate before later updates introduced modular payloads for cryptocurrency theft, credential harvesting, browsing-history exfiltration, social-media account abuse, and fake-update phishing. Some extensions were created by the attackers, while five were reportedly acquired from legitimate developers, including a right-click utility with an estimated 70,000 Chrome users and a related Edge version with roughly 10,000 users, illustrating how automatic extension updates can expand exposure. The extensions establish encrypted WebSocket connections to command-and-control servers, remove websites’ Content Security Policy protections, and dynamically inject malicious JavaScript into visited pages through hidden elements and event handlers. Observed modules target cryptocurrency wallets and exchanges, impersonate Ledger and Trezor recovery workflows to steal seed phrases, collect form inputs and session tokens, and display deceptive browser-update prompts that can encourage users to run attacker-provided commands. Socket linked the operation to techniques reported as early as February 2024 and warned that its rotating infrastructure, dynamically delivered payloads, and use of purchased extensions make it resilient and adaptable; it recommends that users regularly review and remove unnecessary or suspicious browser extensions.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.