Researchers uncovered 19 malicious extensions for Chrome and Edge that deployed a modular malware framework capable of stealing cryptocurrency, sensitive data, and browser history. Five extensions were acquired from original developers and turned malicious through automatic updates, including one with over 70,000 Chrome users later removed by Google. The malware establishes encrypted WebSocket connections to command-and-control servers, removes security headers, and injects malicious scripts into visited websites.
The framework includes modules for draining cryptocurrency wallets, replacing hardware wallet sites with phishing pages, and stealing session tokens from major exchanges. Additional modules harvest credentials, browser history, and display ClickFix-style fake browser updates to execute attacker commands. Users who installed affected extensions should assume credentials are compromised, change passwords, and transfer cryptocurrency assets to new wallets. The campaign may have been active since early 2024, with researchers warning of potential future modules. No malicious extensions remain in the Chrome Web Store, though one Edge version remained available during investigation. The incident highlights ongoing supply-chain risks in browser extension ecosystems and the importance of regular extension audits.
Read more...
