Hackers Use Google Sheets and Tampermonkey to Steal Crypto via Browser Hijack
Cisco Talos has disclosed a high-priority ClickFix campaign in which attackers distribute fake cryptocurrency API vulnerability reports through forums and Telegram to trick users into pasting malicious JavaScript into their own browsers. The injected code establishes persistence via the Tampermonkey browser extension and fetches obfuscated scripts from publicly accessible Google Sheets using the Google Visualization API. Once active, the scripts hook browser fetch requests and clipboard activity, silently replacing legitimate cryptocurrency deposit addresses with attacker-controlled ones. Because the campaign relies entirely on legitimate Google infrastructure and user-trusted sites, the malicious traffic blends into normal browsing activity and largely evades detection. Security researchers recommend managing browser extension allowlists, monitoring script retrievals from Google Sheets APIs, and independently verifying destination wallet addresses through a separate trusted channel.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in