Malicious Chrome and Edge extensions hijacked to steal crypto wallets, browser data
Security firm Socket uncovered a campaign, active since early 2024, in which 16 malware modules were pushed through browser extensions on the Chrome Web Store and Microsoft Edge add-ons store. Five extensions were initially legitimate but were bought from their original developers and later turned malicious via automatic updates, including one tool with roughly 70,000 Chrome users and 10,000 Edge users. Once activated, the extensions connected to remote servers to strip website security headers, inject phishing scripts, and drain cryptocurrency wallets on platforms like Coinbase, Binance, Kraken and MetaMask.