Cybersecurity researchers have identified a group of 18 Google Chrome extensions and one Microsoft Edge extension that possess wallet secret stealing and cryptocurrency draining capabilities. These extensions were published over the last six months and are part of a campaign tracked by Socket security researcher Karlo Zanki, who indicates that the activity may have been ongoing since February 2024.
According to reporting by The Hacker News, the threat actor behind these extensions employs a straightforward method: they either acquire legitimate extensions or release clean versions without malware. After gaining user downloads, they subsequently publish a new version that includes malicious features.
Details of the Malicious Extensions
Out of the identified extensions, 14 were created by the threat actor, while five were purchased from previous owners. Notable extensions include:
- Enable Right Click & Copy — Smart Unlock + OCR (80,000 users)
- QuickLens – Search Screen with Google Lens (previously flagged for malicious behavior)
- Private Crypto News Reader
- Multi-Chain Explorer
The campaign has been described as having a dual functionality, where the extensions appear to work as intended while also connecting to malicious servers to exfiltrate user data and execute arbitrary commands. This behavior has raised concerns about the potential impact on users, particularly given the auto-update feature of Chrome extensions, which can facilitate the spread of malicious updates.
Ongoing Threat and User Risks
The findings suggest that the threat actor has been operating effectively for over two years, indicating a high level of capability. The operational technique of acquiring legitimate extensions and releasing malicious versions poses significant risks to end-users, as highlighted by Zanki. The ability to dynamically change command-and-control (C2) servers further complicates detection and mitigation efforts.
As the cybersecurity landscape continues to evolve, users are urged to remain vigilant about the extensions they install and to monitor for any unusual activity associated with their browser extensions.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



