A massive malware campaign targeting Google Chrome and Microsoft Edge extensions has been uncovered, designed to drain crypto wallets and steal sensitive browser data.

  • 16 malicious modules identified targeting various crypto assets.
  • Attackers hijack 'Connect Wallet' buttons to drain EVM, Solana, and Tron wallets.
  • Malware is delivered via legitimate extension updates.
  • Users are urged to change passwords and move crypto assets immediately.

A sophisticated cyberattack has been uncovered involving multiple extensions for Google Chrome and Microsoft Edge. These malicious tools are part of a malware framework designed to steal cryptocurrency, sensitive personal data, and browser history through highly extensible modules.

The investigation, conducted by application security firm Socket, suggests that this operation may have been active since early 2024. In a chilling twist, many of these extensions were originally legitimate and provided the advertised functionality before being compromised via automatic updates. This means users who trusted these tools for years may have been unknowingly hosting malware.

Why This Matters

BozokMedia analysis shows that the danger lies in the 'trust gap' created by automatic updates. When attackers acquire legitimate extensions from original creators, they can bypass initial scrutiny. Once the malware is active, it establishes encrypted connections to command-and-control (C2) servers, effectively turning a user's browser into a tool for its own exploitation.

The ability of attackers to weaponize legitimate software updates represents one of the most difficult-to-detect vectors in modern cybersecurity.

The scope of the theft is massive. The malware is capable of draining EVM, Solana, and Tron wallets by hijacking legitimate interface buttons. Furthermore, it targets major exchanges including Coinbase, Binance, Kraken, OKX, and MetaMask to steal session tokens and account balances. It even goes as far as replacing the official websites of hardware wallets like Ledger and Trezor with convincing phishing pages to steal seed phrases.

Historical Background of Extension Malware

Browser extensions have long been a target for cybercriminals due to their deep integration with user data. From simple adware to complex data exfiltrators, the evolution of extension-based attacks shows a trend toward more stealthy, modular, and 'extensible' frameworks that can adapt to new security measures in real-time.

Attack VectorMethodologyImpact
Update HijackingInjecting malware into legitimate updatesHigh (Bypasses initial vetting)
Phishing InjectionReplacing legitimate sites with fake onesCritical (Steals Seed Phrases)
ClickFix LuresFake browser update promptsMedium (Social Engineering)
Did You Know?: Attackers use 'ClickFix' lures, which display fake browser error messages to trick users into running malicious commands manually.

Frequently Asked Questions (FAQs)

1. How can I tell if my extension is malicious?
It is difficult to tell visually. The best defense is to minimize the number of extensions you use and monitor for unusual browser behavior or unexpected permission requests.

2. I used the 'Enable Right Click' extension; am I at risk?
Yes. This specific extension was identified as part of the campaign. You should assume your credentials have been compromised and take immediate action.