Eighteen Chrome and Edge Extensions Discovered with Wallet-Stealing and Crypto-Draining Capabilities

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity researchers have identified a group of 18 Google Chrome extensions and one Microsoft Edge extension that possess wallet secret stealing and cryptocurrency draining capabilities. These extensions were published over the last six months and are part of a campaign tracked by Socket security researcher Karlo Zanki, who indicates that the activity may have been ongoing since February 2024.

According to reporting by The Hacker News, the threat actor behind these extensions employs a straightforward method: they either acquire legitimate extensions or release clean versions without malware. After gaining user downloads, they subsequently publish a new version that includes malicious features.

Details of the Malicious Extensions

Out of the identified extensions, 14 were created by the threat actor, while five were purchased from previous owners. Notable extensions include:

  • Enable Right Click & Copy — Smart Unlock + OCR (80,000 users)
  • QuickLens – Search Screen with Google Lens (previously flagged for malicious behavior)
  • Private Crypto News Reader
  • Multi-Chain Explorer

The campaign has been described as having a dual functionality, where the extensions appear to work as intended while also connecting to malicious servers to exfiltrate user data and execute arbitrary commands. This behavior has raised concerns about the potential impact on users, particularly given the auto-update feature of Chrome extensions, which can facilitate the spread of malicious updates.

Ongoing Threat and User Risks

The findings suggest that the threat actor has been operating effectively for over two years, indicating a high level of capability. The operational technique of acquiring legitimate extensions and releasing malicious versions poses significant risks to end-users, as highlighted by Zanki. The ability to dynamically change command-and-control (C2) servers further complicates detection and mitigation efforts.

As the cybersecurity landscape continues to evolve, users are urged to remain vigilant about the extensions they install and to monitor for any unusual activity associated with their browser extensions.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Red Hat releases important kernel security update for RHEL 8.6 Advanced and Extended Support

Red Hat has announced an important kernel security update for Red Hat Enterprise Linux (RHEL) 8.6, specifically targeting the Advanced Mission Critical Update Support...

Unit 42 Warns Frontier AI Models Have Shifted Cybersecurity Power to Attackers

Unit 42, the threat intelligence arm of Palo Alto Networks, has raised alarms about the impact of frontier AI models on cybersecurity, suggesting a...

Invespy Launches Broker Hub to Transform Dubai’s Real Estate Ecosystem

Invespy Launches Broker Hub to Transform Dubai's Real Estate Ecosystem The Invespy Broker Hub has officially launched in Dubai, aiming to revolutionize the real estate...

Major Cyber Breaches Reported: Latvia, Sakura Internet, and SickKids Among Affected

In a week marked by significant cybersecurity incidents, the latest Threat Intelligence Bulletin from Check Point Research highlights major breaches affecting organizations across Europe...