Malicious Chrome & Edge Extensions Steal Crypto Wallets

Cybersecurity researchers have uncovered a coordinated campaign involving 18 malicious Chrome extensions and one for Microsoft Edge, all designed to steal wallet secrets and drain cryptocurrency funds. The extensions, detected over the past six months, share eerie similarities in their code and operational tactics, suggesting a single threat actor orchestrating the scheme.
A Hidden Threat in Plain Sight
Discovered by Socket security researcher Karlo Zanki, these extensions masqueraded as legitimate tools—ranging from ad blockers to productivity boosters—until their true purpose was revealed. Once installed, they surreptitiously extracted private keys, seed phrases, and other sensitive wallet data, then transmitted them to remote servers controlled by the attackers. In some cases, the extensions also injected unauthorized transactions to siphon funds directly from users’ crypto wallets.
How the Campaign Operated
The extensions’ tradecraft points to a methodical approach. Many were disguised under names mimicking popular legitimate extensions, tricking users into installing them from official browser stores. The malicious code leveraged obfuscation techniques to evade detection by automated security scans, while maintaining a low profile to avoid raising suspicion during routine usage. Socket’s analysis indicates that the campaign may still be active, with new variants likely emerging as awareness grows.
Why it matters
This incident underscores the persistent risk of malicious browser extensions, particularly those targeting high-value assets like cryptocurrency. For users, the takeaway is clear: even extensions from official stores can harbor hidden dangers. Regular audits of installed extensions, cautious permission granting, and the use of hardware wallets for large holdings can mitigate risks. For the industry, it highlights the need for stricter vetting processes and real-time behavioral monitoring in extension marketplaces to curb such abuses before they escalate.
Source: The Hacker News. AI-assisted editorial synthesis — TechnoExpress.

