Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Fake imToken Chrome Extension Steals Seed Phrases via Phishing Redirects

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
1,877
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team identified a malicious Chrome extension named lmΤoken Chromophore, masquerading as a color visualizer while imitating the imToken brand to execute phishing attacks. This extension, upon installation, redirects users to a deceptive phishing site through a hardcoded JSONKeeper endpoint, where victims are lured into providing sensitive wallet information like seed phrases or private keys, under the guise of a legitimate wallet recovery process. Despite claims of no data collection and showing 5-star ratings, the extension's true function is to redirect users to phishing pages that impersonate imToken using mixed-script Unicode homoglyphs. imToken, a well-known non-custodial wallet brand, confirmed it has not released a Chrome extension, making this fake extension, which remains live with 39 active users, a significant threat as it leverages the brand's trustworthiness to capture wallet recovery secrets. Socket has reported the extension and its publisher to Google for removal and recommends vigilance against such browser extension lures, emphasizing the importance of verifying software through official channels and inspecting extension packages and their associated infrastructure for security.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 3 1,488 268 99 +7%
LLM 1 6,078 960 218 +18%
MCP 1 4,488 443 150 +34%
Real-time 1 6,457 1,307 242 +28%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.