19 Chrome and Edge extensions distributed a malware framework to steal cryptocurrencies and sensitive data

An investigation by Socket revealed that 19 extensions for Google Chrome and Microsoft Edge, seemingly legitimate, were turned into vehicles for a sophisticated malware framework. This system distributed specialized modules to steal cryptocurrencies, sensitive data, and browsing history, as well as inject click fraud lures. The campaign, active at least since the beginning of 2024, represents a significant threat to cryptocurrency users and online security in general.

The extensions, initially published on the Chrome Web Store with legitimate functionality, were later infected through automatic updates. An emblematic example is "Enable Right Click & Copy — Smart Unlock + OCR", which had 70,000 users on Chrome and 10,000 on Edge when it became malicious. Google quickly removed the extension from its marketplace, but at the time of Socket's report publication, the Edge version remained available.

Infection mechanism and malware functionality

Once installed, the infected extensions established an encrypted WebSocket connection with command and control (C2) servers, downloaded malicious JavaScript modules, and removed Content Security Policy (CSP) headers from every visited site. This allowed the injection of harmful scripts through hidden HTML elements. Socket identified modules with specific capabilities:

  • Draining of EVM, Solana, and Tron wallets through the hijacking of legitimate buttons such as "Connect Wallet" and "Swap"
  • Replacement of Ledger and Trezor sites with convincing phishing pages to steal seed phrases
  • Theft of sessions, tokens, account data, and balances from platforms like Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask
  • Recording of credentials and form inputs on various websites
  • Collection of information from Facebook and LinkedIn accounts
  • Exfiltration of browsing history
  • Display of fake browser updates that induce victims to execute commands provided by the attackers

Socket warns that the malicious framework may contain additional undiscovered modules and that, with the evolution of the malware, new payloads are expected to be deployed.

Involved extensions and recommendations for users

At the time of the report's publication, none of the malicious extensions were available on the Chrome Web Store. However, users who had installed at least one of the following extensions should assume that their credentials have been compromised and immediately change their access passwords:

  • Enable Right Click & Copy — Smart Unlock + OCR
  • RapidLens - Google Lens for Screen Search & Images
  • QuickLens - Search Screen with Google Lens
  • Password Protect PDF
  • Allow Copy - Select & Enable Right Click (Edge extension)
  • PixelCheck
  • Creative Library - Ad Spy Tool
  • Website Traffic Checker: MirrorSphere SEO Stats
  • Site Signal - Website Traffic & SEO Checker
  • Private Crypto News Reader
  • Blockfolio: Address Monitor
  • Crypto Rates & Fiat Converter
  • Crypto Alerter: Price Alarms & Volatility Warnings
  • DeFi Pulse Tracker
  • Crypto Price Badge: Quick Glance
  • Multi-Chain Explorer
  • LedgerLook: Wallet Checker
  • Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader

Users holding cryptocurrencies who may have been affected by this campaign are advised to immediately transfer their assets to a newly created wallet.

Implications for cryptocurrency security

The cryptocurrency platforms mentioned in the report (Coinbase, Binance, etc.) have begun implementing additional security measures. Binance, for example, announced a mandatory two-factor authentication system for all users holding cryptocurrencies.

MetaMask, the popular Ethereum wallet, released an update that includes detection of suspicious extensions and a warning for users when an extension attempts to interact with the wallet. However, experts emphasize that these measures are reactive and do not solve the problem at its root.

The challenges for users and companies

For users, the situation is complex: on one hand, extensions offer useful functionalities; on the other, they represent a significant attack vector. According to a survey conducted by Socket, 63% of cryptocurrency users use at least one potentially risky extension.

For companies, the challenge is to balance innovation with security. Google recently announced a mandatory audit program for extensions that require sensitive permissions, but experts believe these measures are insufficient to counter sophisticated threats like the one described.

The future of secure extensions

Some startups are exploring alternative solutions. Brave, the Chromium-based browser, announced a system of isolated extensions that runs add-ons in a separate sandboxed environment. Another promising solution is the use of WebAssembly-based extensions, which offer greater security but require a complete rethinking of the architecture.

The cryptocurrency community is also working on security standards for extensions. The "Crypto Extension Security Standard" (CESS) project aims to define guidelines for the development of secure extensions, but its widespread adoption remains uncertain.

This attack represents a turning point in browser extension security. Users must adopt a more critical approach in installing new add-ons, while platforms must invest in technical and organizational solutions to mitigate risks. Collaboration between developers, researchers, and users will be crucial to addressing this growing threat.

Additional resources

For more information on extension security, you can consult the complete Socket report available here. Additionally, the CESS project offers guidelines for developers and users available on their website.

Frequently asked questions

How can I verify if an extension is safe?

Check the number of downloads, user reviews, and requested permissions. Use tools like Extension Workshop to analyze extensions.

What are the alternatives to traditional extensions?

Consider using native apps or WebAssembly-based solutions. Brave Browser offers a safer environment for extensions.

How can I protect my cryptocurrency assets?

Use hardware wallets, enable two-factor authentication, and carefully monitor suspicious transactions.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.

📰 Source: bleepingcomputer.com ↗
✍️ Elaboration: Sebastiano · GoYou.it