Check browser: 19 extensions for Chrome and Edge steal cryptocurrency

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
442
Reaction score
718
Deposit
0$
The usual browser extension can work for years without complaints, and then after the usual update, start stealing cryptocurrency and passwords. Socket specialists found 19 malicious add-ons for Chrome and Edge, which downloaded code for stealing crypto wallets, credentials and other sensitive information.

The campaign affected 18 Chrome extensions and one Edge extension. Some of the additions were created by the intruders themselves, but five earlier belonged to legitimate developers. The criminals bought already known extensions with the existing audience, saved the declared functions, and then released a new version with malicious code.

The most notable example was Enable Right Click & Copy – Smart Unlock + OCR. Before the change of owner, the expansion was developed by PreppHint, and by the time the malicious version appeared, about 70 thousand people were used. A similar version for Edge consisted of about 10 thousand users. Thus, the potential audience of the two versions reached 80 thousand people.

This scheme is particularly dangerous because of the browser update mechanism. Chrome by default checks new versions of extensions when you start and then every few hours. The user could install a secure version long before the incident, and the malicious code got into the browser later without re-installing the add-on.

After infection, the extension connected to the control server via WebSocket and received additional JavaScript modules. The malicious code removed the titles of Content Security Policy from the pages, bypassing protection against the introduction of foreign scenarios, after which he launched the downloaded modules directly on the visited sites.

The set of modules allowed you to replace the buttons for connecting crypto wallets and confirming operations, intercept secret phrases of Ledger and Trezor hardware wallets, as well as collect data from open sessions Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit and MetaMask. A separate module followed the input fields on the sites and stole logins, passwords and email addresses. Another scenario showed a fake Chrome update and persuaded the user to run a team prepared by intruders.

Google has already removed the most massive extension from the Chrome Web Store. At the time of publication of Socket, the version for Edge continued to spread, and the specialists handed over the information to Microsoft. As of August 29, the Allow Copy – Select & Enable Right Click page is still available in the official Edge Add-ons store. Having a page in itself does not confirm that the current version still contains malicious code.

The Socket links the discovered extensions to the Superior campaign, the traces of which have been traced back to at least February 2024. Specialists are advised to regularly check the installed additions and remove unnecessary or suspicious extensions, as the change of the owner can turn a long-familiar tool into a source of threat.
 
Top Bottom