19 Chrome and Edge Extensions Discovered with Malicious Wallet-Stealing and Crypto-Draining Code
19 Chrome and Edge extensions were discovered containing malicious code designed to steal cryptocurrency wallet data and drain funds, with the campaign active since at least February 2024. The threat actors used compromised or purchased legitimate extensions to distribute malware, leveraging command-and-control servers and dynamic content injection techniques to exfiltrate user data.
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.
The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
*** END OF TRANSMISSION ***