Chrome and Edge Store Extensions Caught Stealing Crypto and Browser Data

Multiple extensions listed in the Google Chrome Web Store and the Microsoft Edge add-on store were caught delivering a malware framework. That framework deployed modules to steal cryptocurrency, grab sensitive data, vacuum up browser history, and inject ClickFix lures that trick people into running the attackers’ commands.

This did not come from some random forum download. These were sitting in the official stores Google and Microsoft tell regular people to trust.

What the malware framework was built to steal

An extension is not just a little button on your toolbar. Once it is installed, it can load extra jobs later. In this case the jobs were straightforward and ugly.

  • Steal cryptocurrency from wallets used in the browser
  • Grab sensitive data stored or typed in the browser
  • Collect browsing history
  • Inject ClickFix lures into pages you visit

If you keep a crypto wallet in Chrome, log into banks, or just live your life in the browser, that is a full set of things you do not want walking out the door.

ClickFix lures turn you into the installer

ClickFix is a con. You get a fake CAPTCHA or a fake error message that tells you to copy a command and paste it into your computer to prove you are human or to fix a problem. You think you are helping yourself. You just ran their payload.

Pair that with an extension that already has a foot inside the browser, and the store listing becomes the bait. The ClickFix prompt becomes the hook.

The official store was not a safety net

Google has been playing whack-a-mole with bad Chrome extensions for a long time. Microsoft Edge uses a lot of the same Chromium plumbing, so the same junk shows up there too.

Folks install a PDF helper, a coupon clipper, a dark mode switch, or a wallet tool because the store page looks legit and the reviews look fine. Then a module loads, and now it can see the tabs you have open, the data you type, and the coins you thought were sitting safe in a browser wallet.

That is the part that should make you mad. The store is sold as the safe path. For a lot of people at work and at home, it is the only path they know.

What you should do right now

You do not need to panic. You do need to treat every extension like it has keys to the house.

  • Open Chrome or Edge and review every installed extension. If you do not recognize it or do not use it, remove it.
  • Drop anything that has been sitting idle for months. Unused add-ons are extra doors.
  • Do not keep crypto wallets in the same browser profile you use for random browsing and coupon tools.
  • If a website tells you to copy a command and paste it into Run, PowerShell, or Terminal to verify or fix something, stop. That is the ClickFix play.
  • A hardware wallet or a dedicated wallet app beats a browser extension for anything you cannot afford to lose.
  • If you had unknown extensions installed, change passwords for accounts you used in that browser and turn on two-factor authentication that is not text messages if you can.

I have spent decades helping small businesses and regular folks cut through this stuff. The pattern does not change. A shiny store badge is not a background check. If an extension wants permission to read every site you visit, that is not a convenience. That is the whole game.

Audit the list. Cut what you do not need. Keep your money and your logins off the same playground as random add-ons. That is how you keep control of your own data when the stores fail to do it for you.

Primary Source: https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.