Popular Chrome extensions were quietly weaponized to steal crypto from 80,000 users
Some extensions worked as advertised for months before hackers slipped in malicious code
by Alfonso Maruccia · TechSpotServing tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.
Facepalm: Security experts recently uncovered a malicious campaign that had been active for years. Unknown cybercriminals abused Chrome's extension system to infect tens of thousands of systems, and many victims may still be vulnerable if they haven't manually changed their browser's configuration.
Socket Inc. researchers have identified 19 malicious extensions targeting Chrome and Edge users. The cybercriminal campaign primarily targeted Google's browser, but one extension gained significant popularity on both Chrome and Edge. In any case, the analysts believe a single "mind" is behind the campaign – and it's determined to keep going even after the extensions have been removed from both browsers' stores.
All of the malicious add-ons employed a similar strategy, Socket said. A majority of the extensions (14) were developed directly by the cybercriminals, while five others were purchased from legitimate developers and companies. Initially, the add-ons simply provided their advertised functionality. Over the past six months, however, the hackers updated the extensions with malicious code designed to compromise systems or start harvesting users' data.
The list of add-ons included a particularly popular extension named "Enable Right Click & Copy - Smart Unlock + OCR." It was ultimately installed on 70,000 Chrome browsers and another 10,000 Edge browsers. A total of 80,000 users were eventually exposed to the malicious extension, which primarily targeted crypto wallets and other cryptocurrency-related data.
The cybercriminals used some code-based attack patterns that were first identified in February 2024, Socket said. They injected malicious payloads after accumulating a considerable number of potential victims, managing the crypto-stealing campaign remotely through a flexible command-and-control domain infrastructure.
The malicious extensions were eventually removed from the Chrome and Edge stores. However, users might still be part of the C2 infrastructure if they haven't checked for and manually removed all 19 add-ons listed by researchers.
// Related Stories
- Popular Chrome extension "Save Image as Type" was hijacked, impacting over 1 million users
- Chrome's new security feature could make stolen session cookies virtually useless
In 2018, Google announced a major change to the extension technology used by the Chromium project. The Manifest V3 API was intended to improve the security architecture of add-ons across Chromium-based browsers, including Chrome and Microsoft Edge.
As the 19 malicious extensions retrofitted with malicious payloads clearly show, Google's attempt to strengthen security might very well turn out to be wishful thinking. Cybercriminals are likely to continue targeting popular browser extensions even after Manifest V2 is gone.
See more TechSpot in Google Add us as a preferred source and our reporting shows up first when you search.
Add TechSpot