Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Blog post from Socket
Security researchers uncovered a cross-browser campaign involving six Chrome and Firefox extensions linked by shared code, infrastructure, publishing history, and targeting of Axiom Trade and Padre cryptocurrency users. J7Tracker, VREO, and Orbit Tracker automatically collect authenticated session tokens, wallet-related data, browser cookies, Firebase tokens, and application state from logged-in users, then exfiltrate the information through attacker-controlled Vercel and Bonto infrastructure, in some cases using browser navigation to bypass conventional cross-origin restrictions. Earlier Chrome extensions, GhostApe and GhostApe Color, were associated with the same publisher portfolio and appear connected to a repackaging and brandjacking pattern involving the legitimate MockApe tool. Although the Chrome listings were removed in July 2026, Orbit Tracker remained available on Firefox at publication and was reported to Mozilla. Researchers warn that attackers may continue republishing cloned trading extensions under new identities and recommend blocking known extension IDs and domains, revoking potentially exposed sessions and credentials, reviewing wallet activity, monitoring suspicious extension behavior, and limiting extensions in browser profiles used for high-value financial or cryptocurrency accounts.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.