19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Nineteen browser extensions have been linked to a malware operation that steals cryptocurrency wallet secrets, passwords and other data.

The extensions appeared to offer useful tools, including search helpers, price monitors and copy-unlocking features, before later updates quietly introduced the harmful code.

The campaign affects 18 Chrome extensions and one Microsoft Edge extension. Attackers acquired established add-ons with existing users, then used routine automatic updates to deliver harmful new versions. The most exposed pair potentially reached 80,000 users.

Researchers at Socket.dev identified the operation and said the related extensions share a flexible framework for downloading and running fresh payloads. 

Socket.dev said in a report shared with Cyber Security News (CSN) that the campaign mainly pursues wallet theft and cryptocurrency draining, but can also collect credentials, session data and browsing history.

Malicious extension (Source - Socket.dev)
Malicious extension (Source – Socket.dev)

The findings show why an extension is not safe simply because it began legitimate. Code added after publication turned familiar tools into a route for theft, echoing the concerns in compromised Chrome extension campaigns involving browser add-ons that were later weaponized.

19 Chrome and Edge Extensions Caught Stealing

Socket tracked the operation as Superior, based on labels used in its JavaScript modules. Fourteen of the extensions were created by the actors, while five were reportedly bought from legitimate developers.

The clean first releases built trust; later updates added the malware, an approach that can leave users unaware that ownership and risk have changed.

The most exposed listing was Enable Right Click & Copy – Smart Unlock + OCR. Google removed its Chrome version after it was identified, but the research said the matching Edge version was still active and delivering malware at the time of publication.

That distinction matters because removing one store listing does not automatically remove an installed add-on or stop a related version elsewhere.

The software opens an encrypted WebSocket channel to attacker-controlled infrastructure and receives code modules for particular tasks. It can also rotate to a replacement control server and use a separate destination for stolen data.

This layered design makes simple disruption harder and lets the operators change behavior without publishing a visibly different extension.

One key technique removes the browser’s Content Security Policy header from pages a victim visits. That safeguard normally limits which scripts a website can load.

With it gone, the extension can inject code into pages and trigger it through hidden page elements, repeating a tactic described in coverage of malicious Chrome security bypasses.

Wallet Drainers and Password Theft

The downloaded modules target several high-value paths. A wallet drainer detects EVM, Solana and Tron wallets, then replaces genuine Connect Wallet or Swap button behavior with attacker-controlled approval requests.

Another module presents convincing recovery or update screens to capture seed phrases, which can give criminals complete control of a wallet.

Other modules target logged-in exchange and wallet sessions, collecting cookies, access tokens, profile information and balances from services including Coinbase, Binance, Kraken and MetaMask.

JavaScript Injection (Source - Socket.dev)
JavaScript Injection (Source – Socket.dev)

A universal form grabber records text, email and password fields across visited sites. That breadth raises the stakes beyond crypto: personal accounts and workplace logins may also be exposed.

The campaign also includes social-media data theft, browsing-history collection and fake browser-update prompts. Those prompts can copy an attacker command to the clipboard and tell a victim to paste it into their computer.

Readers should treat unexpected update instructions as suspicious, especially when a website asks them to run a command, as shown by recent fake wallet update lures.

Users should review installed extensions now, remove those they do not need and examine any add-on that recently changed publisher or permissions.

People who used an affected extension should change passwords from a clean device, revoke active sessions where possible and move cryptocurrency to a new wallet if a recovery phrase may have been entered.

Teams should inventory browser extensions and watch for unusual outbound connections, applying lessons from malicious Firefox add-on investigations.

Indicators of Compromise (IoCs):-

Type Indicator Description
C2 domain active-enable-right-click[.]top Primary command-and-control domain
C2 domain api[.]enable-right-click[.]click Primary command-and-control domain
C2 domain enable-right-click[.]click Primary command-and-control domain
C2 domain payload[.]siteinsight[.]bond Primary command-and-control domain
C2 domain api[.]extensionanalyticspro[.]top Primary command-and-control domain
C2 domain password-protect-pdf[.]com Primary command-and-control domain
C2 domain privatecryptonewsreader[.]pro Primary command-and-control domain
C2 domain cryptoratesfiatconverter[.]pro Primary command-and-control domain
C2 domain cryptopricebadgequickglance[.]pro Primary command-and-control domain
C2 domain ws[.]site-signal[.]top Primary command-and-control domain
C2 domain content[.]resonanceweb[.]top Primary command-and-control domain
C2 domain api[.]creativelibrary[.]top Primary command-and-control domain
C2 domain api[.]codefilearc[.]net Primary command-and-control domain
C2 domain ws[.]seopulsepro[.]sbs Primary command-and-control domain
C2 domain relay[.]seopulsepro[.]sbs Primary command-and-control domain
C2 domain defipulsetracker[.]pro Primary command-and-control domain
C2 domain blockfolioaddressmonitor[.]pro Primary command-and-control domain
C2 domain pricealarmsvolatilitywarnings[.]pro Primary command-and-control domain
C2 domain extension[.]io-safe[.]icu Primary command-and-control domain
C2 domain feedback[.]feedx-ray[.]top Primary command-and-control domain
Secondary C2 domain lucky-random[.]sbs Secondary command-and-control endpoint
Exfiltration domain pipi[.]saghirmohamed19[.]workers[.]dev Cloudflare Worker data-exfiltration sink
Exfiltration domain mimi[.]saghirmohamed19[.]workers[.]dev Cloudflare Worker data-exfiltration sink
Payload-hosting domain cookie-whitelist[.]top Wallet drainer script hosting
Payload-hosting domain whale-alert[.]art Wallet drainer script hosting
Payload-hosting domain ggle-analytics[.]com Fake browser-update page hosting
Related domain cookie-whitelist[.]com Related domain reported in DomainTools research
Related domain whale-alert[.]life Related domain reported in DomainTools research
Chrome extension ID pkoccklolohdacbfooifnpebakpbeipc Enable Right Click & Copy – Smart Unlock + OCR
Chrome extension ID fegckejpfnlmfgkfjpinlbgmeeijjkel RapidLens – Google Lens for Screen Search & Images
Chrome extension ID kdenlnncndfnhkognokgfpabgkgehodd QuickLens – Search Screen with Google Lens
Chrome extension ID jamminefolhgepgihbmcjjhgldbfcikp Password Protect PDF
Edge extension ID inmkjedjdhgpknjogbjomhnbgdccckkg Allow Copy – Select & Enable Right Click
Chrome extension ID fcgdejjichpgfaaafflplhfijcnieopb PixelCheck
Chrome extension ID cfpnjdbpojpcongfaefcamjbaolpelcd Creative Library – Ad Spy Tool
Chrome extension ID aapdalkmclfaahehnmicbglkohkldhne Website Traffic Checker: MirrorSphere SEO Stats
Chrome extension ID dkdadldmiefjldmegbjbnhhfddnkhlhm Site Signal – Website Traffic & SEO Checker
Chrome extension ID fjmlhlkccegopebcllcmafahkmeejpph SEO Pulse Pro – Website Traffic & SEO Analyzer
Chrome extension ID iekoapohahgmogbagegmcgplbkikcgke Private Crypto News Reader
Chrome extension ID ahpnnnjbnfbhoikhohglpohnoocjcoco Blockfolio: Address Monitor
Chrome extension ID oeacadlaclegkkkdehjmiifnjhcekclj Crypto Rates & Fiat Converter
Chrome extension ID jmlgannjlbliikgcaieomgmcnfplglea Crypto Alerter: Price Alarms & Volatility Warnings
Chrome extension ID lhmcajhgadanidbopgaoobjlldegjmke DeFi Pulse Tracker
Chrome extension ID gfackggoapepdmnjnkblogdcjpgcjiak Crypto Price Badge: Quick Glance
Chrome extension ID hfijkbdkpidafdbeebnnkhfccildbcle Multi-Chain Explorer
Chrome extension ID pcngchfbfgejllcbhmeadjhiebebiome LedgerLook: Wallet Checker
Chrome extension ID aodkjdeghbjiaienipfjkbpcikkacbcp Meta & Facebook Ad Library Spy – Save Ads, Finder, Downloader | FeedX-Ray

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post 19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords appeared first on Cyber Security News.