AUTO-UPDATED

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

Cybersecurity researchers have identified 19 malicious Google Chrome and Microsoft Edge extensions that use sophisticated update tactics to steal cryptocurrency and sensitive user data from unsuspecting victims.

Key Points

  • Socket researchers identified 19 malicious extensions, including 14 created by threat actors and five legitimate tools purchased to distribute malware.
  • The campaign, tracked as "Superior," has been active since February 2024 and utilizes automatic browser updates to push malicious code to existing users.
  • Malicious capabilities include harvesting seed phrases, draining cryptocurrency wallets, and stealing credentials from platforms like Facebook and LinkedIn.
  • The "Enable Right Click & Copy" extension, which has approximately 80,000 users, is among the most significant threats identified in the cluster.
  • Attackers employ dynamic command-and-control servers to rotate infrastructure, effectively reducing detection risks and enabling targeted data exfiltration.

Why it Matters

This campaign highlights a critical vulnerability in browser extension ecosystems where legitimate, trusted tools can be weaponized through routine software updates. Users should remain cautious of browser extensions that request excessive permissions, as these tools can bypass security headers to inject malicious scripts directly into web pages.
Internet Published by info@thehackernews.com (The Hacker News)
Read original