Chrome and Edge Users Hit by Stealthy Wallet-Draining Malware
Malicious Chrome and Edge extensions have targeted cryptocurrency wallets, login credentials, browser sessions, and browsing data in a malware campaign that may date back to early 2024.
Researchers at Socket identified 19 malicious modules used by the campaign. None of the affected extensions remain available on the Chrome Web Store.
Legitimate extensions were later weaponized
Many extensions initially worked normally and contained no malicious code when developers first published them.
Socket says attackers later acquired five extensions from their original developers and pushed malicious functionality through automatic updates. This approach allowed the extensions to build trust and users before turning malicious.
Malware injects scripts into websites
After infection, the malware establishes an encrypted WebSocket connection with command-and-control servers and downloads additional JavaScript modules.
It can remove Content Security Policy headers from websites and inject malicious scripts through hidden HTML elements.
The modules can also steal browser history, account information, sessions, tokens, balances, and data entered into web forms.
Cryptocurrency wallets are a major target
The malware can hijack cryptocurrency wallet buttons and replace legitimate Ledger and Trezor pages with fake seed-phrase forms.
Researchers found modules targeting Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask.
Other modules can capture Facebook and LinkedIn credentials.
Some components also use ClickFix attacks. They show fake browser update warnings that attempt to convince users to run malicious commands on their PCs.
Users should secure affected accounts
Socket warns that attackers could add more modules and payloads as the campaign evolves.
Anyone who installed an affected extension should consider their credentials compromised, change passwords, and secure affected accounts. Cryptocurrency users should consider moving assets to a newly created wallet.
In other security news, Claude sessions have been stolen by malware, while OpenAI detailed how it lost control over 1,200 agents before the Hugging Face breach. Meanwhile, two SharePoint flaws can give attackers a path to remote code execution.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages