Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Threat Intelligence
  5. 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

Scheduled Pinned Locked Moved Threat Intelligence
microsoftgooglechrome
1 Posts 1 Posters 3 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Cybersecurity researchers have uncovered a cluster of 18 Google Chrome extensions and one Microsoft Edge extension that were published over the past six months, all carrying hidden wallet secret-stealing and cryptocurrency-draining capabilities. According to security researcher Karlo Zanki at Socket, the extensions share notable similarities in code structure and operational tradecraft, strongly suggesting a coordinated campaign.

    The extensions were designed to harvest wallet secrets and drain cryptocurrency funds from unsuspecting users. While the exact distribution numbers remain unclear, the fact that these were available through official browser stores underlines the growing sophistication of supply-chain attacks targeting browser extensions.

    • Affected platforms: Google Chrome (18 extensions) and Microsoft Edge (1 extension)
    • Publication window: Last six months
    • Key capability: Wallet secret extraction and crypto-asset draining

    Evidence indicates the campaign may have been active for an extended period, with the code showing deliberate efforts to evade detection through commonalities in obfuscation and behavior. Users who have installed any browser extensions recently, especially those related to crypto wallets or trading, are advised to audit their installed add-ons and review permissions carefully.

    Source: The Hacker News

    With the increasing prevalence of malicious browser extensions, has your organization implemented any specific controls to vet or monitor extension permissions across employee devices?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World