started · updated
Browser extensions weaponized in cryptocurrency theft campaign
Researchers at Socket have uncovered a supply chain campaign involving 19 malicious extensions for Google Chrome and Microsoft Edge. The campaign utilized both newly created extensions and those acquired from legitimate publishers to distribute malware through automatic updates.
Five of the extensions were originally developed by legitimate creators before being acquired by threat actors. One such extension, ‘Enable Right Click & Copy — Smart Unlock + OCR’, had approximately 70,000 Chrome users and 10,000 Edge users when the malicious code was introduced. While Google has removed the affected extensions from its marketplace, some versions reportedly remained available on the Edge add-ons store at the time of reporting.
The malware is designed to be highly extensible, establishing encrypted connections to command-and-control servers to download JavaScript modules. Its primary objectives include cryptocurrency theft by hijacking ‘Connect Wallet’ and ‘Swap’ buttons, draining wallets on networks such as EVM, Solana, and Tron. Additionally, the malware can replace legitimate hardware wallet websites with phishing pages, steal session tokens and account data from major exchanges like Coinbase and Binance, and record credentials and form entries across visited websites. To facilitate these attacks, the malware removes Content Security Policy (CSP) headers from websites, allowing attacker-supplied code to run within the user's browser sessions.