Malicious Chrome and Edge Extensions Hijack Crypto Wallets and Steal Sensitive Data
A sophisticated malware framework, distributed through seemingly legitimate extensions on both **Google Chrome** and **Microsoft Edge**, has been uncovered. This campaign leverages 19 distinct modules to drain cryptocurrency wallets, exfiltrate sensitive user data, and hijack browser activity, posing a significant threat to IT security professionals and privacy-conscious users alike.
Multiple extensions for **Google Chrome** and **Microsoft Edge** have been found delivering a potent malware framework. This framework deploys a variety of modules designed to steal cryptocurrency, sensitive data, and browser history, while also injecting **ClickFix** lures.
Application security company **Socket** uncovered this operation, noting that the investigation suggests the campaign may have been active since early 2024. Researchers highlight the 'highly extensible' nature of the 19 malicious modules identified, each serving distinct nefarious purposes.
### How the Malware Infiltrated
**Socket**'s analysis reveals that many of these extensions initially offered their advertised functionality without any malicious code when first published on the **Chrome Web Store**. However, five of these extensions were subsequently acquired from their original creators. Malicious updates were then pushed automatically to users, transforming benign tools into potent threats.
A prime example is the "Enable Right Click & Copy β Smart Unlock + OCR" extension. This particular extension had a user base of at least 70,000 on Chrome and 10,000 on Edge when it turned malicious. While **Google** quickly identified and removed the threat from its marketplace, the Edge version remained available at the time of **Socket**'s initial report.

### The Malware's Modus Operandi
Upon installation, the malware establishes an encrypted WebSocket connection with its command-and-control (C2) servers. It then downloads various JavaScript modules, systematically removes **Content Security Policy (CSP)** headers from visited websites, and injects malicious scripts through hidden HTML elements.
**Socket** observed a wide array of capabilities within the malware modules, including:
* Draining **EVM**, **Solana**, and **Tron** wallets by hijacking legitimate "Connect Wallet" and "Swap" buttons.
* Replacing **Ledger** and **Trezor** websites with convincing seed-phrase phishing pages.
* Stealing sessions, tokens, account data, and balances from major cryptocurrency platforms like **Coinbase**, **Binance**, **Kraken**, **OKX**, **MEXC**, **KuCoin**, **Bybit**, and **MetaMask**.
* Recording credentials and form entries across various websites.
* Harvesting **Facebook** and **LinkedIn** account information.
* Exfiltrating complete browser history.
* Displaying **ClickFix**-style fake browser updates, prompting victims to execute attacker-provided commands.

### Ongoing Threat and Mitigation
**Socket** warns that the malicious framework likely possesses additional undiscovered modules and is expected to evolve with new payloads over time. While none of the malicious extensions are currently available in the **Chrome Web Store**, users should remain vigilant.
**Socket**'s full report provides a comprehensive list of extension IDs implicated in the campaign, along with the domains used for C2 communication:
| Extension ID | Extension Name |
| :----------- | :------------- |
| pkoccklolohdacbfooifnpebakpbeipc | Enable Right Click & Copy β Smart Unlock + OCR |
| fegckejpfnlmfgkfjpinlbgmeeijjkel | RapidLens - Google Lens for Screen Search & Images |
| kdenlnncndfnhkognokgfpabgkgehodd | QuickLens - Search Screen with Google Lens |
| jamminefolhgepgihbmcjjhgldbfcikp | Password Protect PDF |
| inmkjedjdhgpknjogbjomhnbgdccckkg | Allow Copy - Select & Enable Right Click *(Edge extension)* |
| fcgdejjichpgfaaafflplhfijcnieopb | PixelCheck |
| cfpnjdbpojpcongfaefcamjbaolpelcd | Creative Library - Ad Spy Tool |
| aapdalkmclfaahehnmicbglkohkldhne | Website Traffic Checker: MirrorSphere SEO Stats |
| dkdadldmiefjldmegbjbnhhfddnkhlhm | Site Signal - Website Traffic & SEO Checker |
| fjmlhlkccegopebcllcmafahkmeejpph | SEO Pulse Pro - Website Traffic & SEO Analyzer |
| iekoapohahgmogbagegmcgplbkikcgke | Private Crypto News Reader |
| ahpnnnjbnfbhoikhohglpohnoocjcoco | Blockfolio: Address Monitor |
| oeacadlaclegkkkdehjmiifnjhcekclj | Crypto Rates & Fiat Converter |
| jmlgannjlbliikgcaieomgmcnfplglea | Crypto Alerter: Price Alarms & Volatility Warnings |
| lhmcajhgadanidbopgaoobjlldegjmke | DeFi Pulse Tracker |
| gfackggoapepdmnjnkblogdcjpgcjiak | Crypto Price Badge: Quick Glance |
| hfijkbdkpidafdbeebnnkhfccildbcle | Multi-Chain Explorer |
| pcngchfbfgejllcbhmeadjhiebebiome | LedgerLook: Wallet Checker |
| aodkjdeghbjiaienipfjkbpcikkacbcp | Meta & Facebook Ad Library Spy β Save Ads, Finder, Downloader | FeedX-Ray |
Users who have installed any of these extensions should immediately assume their credentials have been compromised and change all login passwords. Cryptocurrency holders potentially affected by this campaign are strongly advised to transfer their assets to a newly created, secure wallet as soon as possible.