<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Chrome Web Store extensions caught stealing crypto, browser data]]></title><description><![CDATA[<p dir="auto">Security researchers have uncovered a malicious campaign targeting users of <strong>Google Chrome</strong> and <strong>Microsoft Edge</strong> through extensions distributed on their official stores. The operation delivered a modular malware framework capable of exfiltrating cryptocurrency, sensitive user data, and browsing history, while also injecting <em>ClickFix</em> social engineering lures into web sessions.</p>
<p dir="auto">The extension set acted as a delivery mechanism for a multi-stage payload. Once installed, the framework deployed individual modules designed to perform specific malicious tasks, including credential harvesting and crypto wallet draining. The <em>ClickFix</em> injection technique presents users with fake error prompts that trick them into copying and running malicious commands, which can lead to further system compromise.</p>
<p dir="auto">Key details from the investigation include:</p>
<ul>
<li>Malicious extensions were available on both the <strong>Chrome Web Store</strong> and <strong>Microsoft Edge Add-ons</strong> store, bypassing initial security reviews.</li>
<li>The framework's modules targeted <strong>browser history</strong>, <strong>cookies</strong>, and <strong>cryptocurrency wallet data</strong>.</li>
<li><em>ClickFix</em> lures were injected into legitimate web pages to trick users into executing PowerShell commands or other harmful scripts.</li>
<li>The campaign appears to be ongoing, with new extensions potentially added over time.</li>
</ul>
<p dir="auto">Users who installed any suspicious extensions should immediately remove them, revoke permissions granted to those extensions, and check for unauthorized transactions in their crypto wallets. Additionally, clearing browser cache and cookies, and resetting any credentials stored in the browser, is strongly recommended.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Do you have visibility into your organization's approved browser extension list, and how do you enforce it against store-hosted threats?</p>
]]></description><link>https://xploitlk.com/topic/155/chrome-web-store-extensions-caught-stealing-crypto-browser-data</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 15:02:29 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/155.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 30 Aug 2026 14:30:30 GMT</pubDate><ttl>60</ttl></channel></rss>