Malicious Browser Extensions Steal Crypto Wallets and Credentials via Silent Updates
Security researchers at Socket Threat Research have identified a campaign, tracked as 'Superior', in which threat actors published or purchased legitimate Chrome and Edge browser extensions before pushing malicious updates to existing users. Once updated, the extensions connected to a command-and-control server to receive encrypted JavaScript modules capable of stealing cryptocurrency wallet recovery phrases, login credentials, session tokens, and browsing history. The malicious code also stripped Content Security Policy headers from web pages, allowing it to intercept wallet operations and hijack legitimate on-page actions such as Connect Wallet and Swap buttons. Additionally, the extensions displayed fake full-screen prompts mimicking Ledger and Trezor interfaces, as well as ClickFix-style alerts that tricked users into executing malicious commands locally on their devices. Because browser extensions update automatically and ownership transfers are not disclosed to users, the campaign was able to reach established user bases without triggering new installation warnings.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in