Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
1,617
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

Security researchers uncovered a cross-browser campaign involving six Chrome and Firefox extensions linked by shared code, infrastructure, publishing history, and targeting of Axiom Trade and Padre cryptocurrency users. J7Tracker, VREO, and Orbit Tracker automatically collect authenticated session tokens, wallet-related data, browser cookies, Firebase tokens, and application state from logged-in users, then exfiltrate the information through attacker-controlled Vercel and Bonto infrastructure, in some cases using browser navigation to bypass conventional cross-origin restrictions. Earlier Chrome extensions, GhostApe and GhostApe Color, were associated with the same publisher portfolio and appear connected to a repackaging and brandjacking pattern involving the legitimate MockApe tool. Although the Chrome listings were removed in July 2026, Orbit Tracker remained available on Firefox at publication and was reported to Mozilla. Researchers warn that attackers may continue republishing cloned trading extensions under new identities and recommend blocking known extension IDs and domains, revoking potentially exposed sessions and credentials, reviewing wallet activity, monitoring suspicious extension behavior, and limiting extensions in browser profiles used for high-value financial or cryptocurrency accounts.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.