Malicious Chrome and Edge Extensions Deploy Crypto Wallet Drainers
Security researchers uncover 19 weaponized browser extensions using a modular framework to steal cryptocurrency and credentials.
A sophisticated malware campaign targeting Google Chrome and Microsoft Edge users has been uncovered, utilizing a network of malicious extensions to drain cryptocurrency wallets and steal sensitive browser data. The operation leverages a highly extensible framework to deploy targeted payloads to unsuspecting users.
Security firm Socket identified 19 malicious extensions in total: 18 targeting Chrome and one targeting Edge. The attackers employed a calculated supply-chain strategy, publishing new extensions or acquiring established ones from their original creators. Five of these extensions were acquired and subsequently weaponized via automatic updates, pushing malicious modules to a pre-existing, trusting user base. One such tool, 'Enable Right Click & Copy — Smart Unlock + OCR,' had at least 70,000 Chrome users and 10,000 Edge users by the time it became malicious.
A Modular Theft Framework
The campaign is powered by a malware framework consisting of at least 16 distinct modules, each designed for specific theft or injection tasks. To maintain control and evade detection, the framework establishes encrypted WebSocket connections to command-and-control (C2) servers. These connections allow attackers to deploy various payloads dynamically, including wallet drainers and "ClickFix" lures.
Technically, the malware operates by removing Content Security Policy (CSP) headers and injecting malicious scripts through hidden HTML elements. This allows the framework to bypass standard browser security protections that would typically block unauthorized script execution.
The Risk to Crypto Users
This campaign represents a significant escalation in browser-based supply chain attacks. By targeting major cryptocurrency exchanges such as Binance and Coinbase, as well as EVM, Solana, and Tron wallets, the attackers can effectively drain digital assets and steal session tokens. Because the malware is delivered through extensions that users have already installed and trusted, the risk of infection is high, and the theft often occurs without the user noticing any immediate red flags.
Future Outlook
The campaign has been active since early 2024, highlighting a growing trend where legitimate tools are sold to malicious actors to gain instant access to thousands of users. Because the framework is designed to be highly extensible, security experts warn that attackers can continue to evolve their payloads to target new wallets or bypass updated security measures. Users are encouraged to audit their installed extensions and remain vigilant regarding automatic updates from tools with new ownership.