Chrome Web Store extensions caught stealing crypto, browser data

Refract AI Intelligence Digest

BLUF

Compromised browser extensions are actively exfiltrating crypto assets and sensitive user data while deploying social engineering lures.

NEWS

Security researchers identified multiple malicious extensions on the Chrome Web Store that function as a malware framework targeting both Google Chrome and Microsoft Edge users. These extensions deploy modules designed to harvest cryptocurrency wallets, browser history, and other sensitive information, alongside injecting ClickFix scam pages.

Why I Care

This threat directly impacts financial security and privacy for millions of browser users, as trusted extension repositories are being abused to bypass traditional security controls. The inclusion of ClickFix lures indicates a multi-stage attack chain that can lead to further credential theft or ransomware infection.

Next Steps

Users should immediately audit and remove unused or suspicious extensions from their browsers, while IT administrators must enforce strict extension allowlisting policies by the end of this week. Organizations should also enable browser security features that warn about malicious extensions and monitor for unusual data exfiltration traffic.

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.