Eighteen Chrome and Edge Extensions Discovered with Wallet-Stealing and Crypto-Draining Capabilities

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity researchers have identified a group of 18 Google Chrome extensions and one Microsoft Edge extension that possess wallet secret stealing and cryptocurrency draining capabilities. These extensions were published over the last six months and are part of a campaign tracked by Socket security researcher Karlo Zanki, who indicates that the activity may have been ongoing since February 2024.

According to reporting by The Hacker News, the threat actor behind these extensions employs a straightforward method: they either acquire legitimate extensions or release clean versions without malware. After gaining user downloads, they subsequently publish a new version that includes malicious features.

Details of the Malicious Extensions

Out of the identified extensions, 14 were created by the threat actor, while five were purchased from previous owners. Notable extensions include:

  • Enable Right Click & Copy — Smart Unlock + OCR (80,000 users)
  • QuickLens – Search Screen with Google Lens (previously flagged for malicious behavior)
  • Private Crypto News Reader
  • Multi-Chain Explorer

The campaign has been described as having a dual functionality, where the extensions appear to work as intended while also connecting to malicious servers to exfiltrate user data and execute arbitrary commands. This behavior has raised concerns about the potential impact on users, particularly given the auto-update feature of Chrome extensions, which can facilitate the spread of malicious updates.

Ongoing Threat and User Risks

The findings suggest that the threat actor has been operating effectively for over two years, indicating a high level of capability. The operational technique of acquiring legitimate extensions and releasing malicious versions poses significant risks to end-users, as highlighted by Zanki. The ability to dynamically change command-and-control (C2) servers further complicates detection and mitigation efforts.

As the cybersecurity landscape continues to evolve, users are urged to remain vigilant about the extensions they install and to monitor for any unusual activity associated with their browser extensions.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Hasbro Notifies Employees of Data Breach Exposing Personal Information

Toy and game giant Hasbro is notifying employees that their personal information may have been compromised in a data breach. The notifications sent to affected...

Australian Authorities Arrest Two Alleged Members of Hacking Group TeamPCP Behind Global Supply-Chain Attacks

Authorities in Australia announced the arrest of two men linked to TeamPCP, a notorious hacking group responsible for a series of global supply-chain attacks...

UAE Phishing Protection Market Expected to Grow Significantly by 2028

The phishing protection market in the UAE is poised for significant growth, with projections indicating a robust expansion by 2028. This development is underscored...

Malicious object blocks on ICS computers drop to 19.15% in Q2 2026, lowest since 2022.

Declining Threats in Industrial Control Systems: A Q2 2026 Overview In a notable shift within the cybersecurity landscape, the percentage of Industrial Control Systems (ICS)...