Particle.news

19 Chrome and Edge Extensions Infected With Crypto‑Stealing Malware

Delisted by the browser stores, the infected add‑ons remain on users' devices and pose ongoing risks to passwords and crypto wallets.

Overview

  • Security firm Socket disclosed on August 27 that researchers found 19 Chrome and Edge extensions running malicious code that could harvest passwords, browser history, social profile data and drain Solana, Tron and EVM-compatible wallets.
  • The attackers built trust by publishing some extensions themselves and by buying five legitimate add‑ons, then pushing malicious updates after the extensions had gained users.
  • The malware could read page content and stored credentials, capture data from Facebook and LinkedIn, and send wallet‑draining commands to users' crypto accounts.
  • Google and Microsoft removed the listed extensions from their stores, but installed copies stay on users' browsers so researchers advise manual uninstallation, resetting passwords, and auditing any crypto wallets tied to the device.
  • The campaign highlights how broad extension permissions and post‑sale code changes let attackers persist on devices, so users should review installed add‑ons and limit permissions to reduce future risk.