Chrome Web Store extensions caught stealing crypto, browser data
BLUF
Compromised browser extensions are actively exfiltrating crypto assets and sensitive user data while deploying social engineering lures.
NEWS
Security researchers identified multiple malicious extensions on the Chrome Web Store that function as a malware framework targeting both Google Chrome and Microsoft Edge users. These extensions deploy modules designed to harvest cryptocurrency wallets, browser history, and other sensitive information, alongside injecting ClickFix scam pages.
Why I Care
This threat directly impacts financial security and privacy for millions of browser users, as trusted extension repositories are being abused to bypass traditional security controls. The inclusion of ClickFix lures indicates a multi-stage attack chain that can lead to further credential theft or ransomware infection.
Next Steps
Users should immediately audit and remove unused or suspicious extensions from their browsers, while IT administrators must enforce strict extension allowlisting policies by the end of this week. Organizations should also enable browser security features that warn about malicious extensions and monitor for unusual data exfiltration traffic.
Source: BleepingComputer ·