Malicious Browser Extensions Targeting Cryptocurrencies
Recent investigations by cybersecurity experts have revealed a troubling scheme involving 19 malicious browser extensions designed to pilfer cryptocurrencies. According to research by Socket, a security firm, these extensions include 18 targeted at Google Chrome and one for Microsoft Edge, identified as having been published or weaponized in the last six months, with origins potentially tracing back to February 2024.
Methods of Operation
The threat actors behind this operation utilized various tactics, including:
- Creating seemingly legitimate extensions
- Acquiring existing ones from their original developers before turning them malicious
Out of the 19 extensions identified, 14 were developed by these malicious actors, while the remaining five were purchased from authentic creators.
Notable Malicious Extensions
Among these extensions, “Enable Right Click & Copy — Smart Unlock + OCR” stands out as particularly dangerous, having reached approximately 70,000 users on Chrome before its malicious functions were uncovered. Currently, although the Chrome extension has been removed from the Chrome Web Store, the Edge version still remains in circulation with around 10,000 users.
Capabilities of the Malware
Socket’s research highlights that this malware is capable of dismantling Content Security Policy protections on various websites. Additionally, the investigators have noted that the campaign includes a sophisticated multi-chain cryptocurrency wallet drainer, which targets Ethereum-Virtual-Machine compatible wallets, as well as those on platforms like Solana and Tron.
The malicious extensions manipulate standard features like “Connect Wallet” and “Swap” buttons to reroute users toward fraudulent transaction processes controlled by attackers. Furthermore, the malware implements deceptive tactics aimed at hardware wallet users by presenting convincing phony Ledger and Trezor recovery or update pages to entice victims into divulging their seed phrases.
Broader Impact and Recommendations
This expansive campaign is designed to harvest authenticated sessions and sensitive account details from leading cryptocurrency exchanges such as Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, and Bybit, along with the popular cryptocurrency wallet, MetaMask. Other modules are engineered to hijack Facebook and LinkedIn accounts, siphon browsing history, and utilize ClickFix-style fake browser update prompts.
To mitigate the risks posed by these malicious extensions, Socket strongly recommends that users regularly audit their installed browser extensions and eliminate any that appear suspicious.