Chrome and Edge Users Hit by Stealthy Wallet-Draining Malware


chrome edge malware
Image credit: Google, Microsoft

Malicious Chrome and Edge extensions have targeted cryptocurrency wallets, login credentials, browser sessions, and browsing data in a malware campaign that may date back to early 2024.

Researchers at Socket identified 19 malicious modules used by the campaign. None of the affected extensions remain available on the Chrome Web Store.

Legitimate extensions were later weaponized

Many extensions initially worked normally and contained no malicious code when developers first published them.

Socket says attackers later acquired five extensions from their original developers and pushed malicious functionality through automatic updates. This approach allowed the extensions to build trust and users before turning malicious.

Malware injects scripts into websites

After infection, the malware establishes an encrypted WebSocket connection with command-and-control servers and downloads additional JavaScript modules.

It can remove Content Security Policy headers from websites and inject malicious scripts through hidden HTML elements.

The modules can also steal browser history, account information, sessions, tokens, balances, and data entered into web forms.

Cryptocurrency wallets are a major target

The malware can hijack cryptocurrency wallet buttons and replace legitimate Ledger and Trezor pages with fake seed-phrase forms.

Researchers found modules targeting Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask.

Other modules can capture Facebook and LinkedIn credentials.

Some components also use ClickFix attacks. They show fake browser update warnings that attempt to convince users to run malicious commands on their PCs.

Users should secure affected accounts

Socket warns that attackers could add more modules and payloads as the campaign evolves.

Anyone who installed an affected extension should consider their credentials compromised, change passwords, and secure affected accounts. Cryptocurrency users should consider moving assets to a newly created wallet.

In other security news, Claude sessions have been stolen by malware, while OpenAI detailed how it lost control over 1,200 agents before the Hugging Face breach. Meanwhile, two SharePoint flaws can give attackers a path to remote code execution.

Via BleepingComputer

More about the topics: browser extension, Chrome, Crypto Wallet, Edge, malware

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages