Fake imToken Chrome Extension Steals Seed Phrases via Phishing Redirects
Blog post from Socket
Socket's Threat Research Team identified a malicious Chrome extension named lmΤoken Chromophore, masquerading as a color visualizer while imitating the imToken brand to execute phishing attacks. This extension, upon installation, redirects users to a deceptive phishing site through a hardcoded JSONKeeper endpoint, where victims are lured into providing sensitive wallet information like seed phrases or private keys, under the guise of a legitimate wallet recovery process. Despite claims of no data collection and showing 5-star ratings, the extension's true function is to redirect users to phishing pages that impersonate imToken using mixed-script Unicode homoglyphs. imToken, a well-known non-custodial wallet brand, confirmed it has not released a Chrome extension, making this fake extension, which remains live with 39 active users, a significant threat as it leverages the brand's trustworthiness to capture wallet recovery secrets. Socket has reported the extension and its publisher to Google for removal and recommends vigilance against such browser extension lures, emphasizing the importance of verifying software through official channels and inspecting extension packages and their associated infrastructure for security.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 1,488 | 268 | 99 | +7% |
| LLM | 1 | 6,078 | 960 | 218 | +18% |
| MCP | 1 | 4,488 | 443 | 150 | +34% |
| Real-time | 1 | 6,457 | 1,307 | 242 | +28% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.