Chrome Web Store Extensions Caught Stealing Crypto and Your Browser Data

Multiple extensions for Google Chrome and Microsoft Edge were caught delivering a malware framework. That framework deployed modules to steal cryptocurrency, lift sensitive data, copy browser history, and inject ClickFix lures.

This is the kind of story that should make regular people sit up. You install something from the official store because you figure Google or Microsoft already checked it. Then it turns around and picks your pocket.

What these extensions were doing

The extensions did not just sit there looking helpful. Once they landed on a machine, they delivered a malware framework. Extra modules then went to work on the real job.

  • Steal cryptocurrency from wallets tied to the browser
  • Grab sensitive data sitting in the browser
  • Copy browser history
  • Inject ClickFix lures that try to trick you into running the next stage yourself

ClickFix is a social engineering trick. You get a fake error or a fake fix prompt, and it tries to get you to copy and paste a command. The malware does not always have to smash the door in if it can talk you into opening it.

Why the official store is not a safety net

Chrome and Edge both run curated stores. People treat that badge like a lock on the door. Attackers know that. They wrap malware in something that looks useful, wait for the review process to miss it, and then harvest whatever they can once enough people click Install.

It pisses me off because the people who get hit are not security researchers. They are small business owners, folks paying bills online, and people with a little crypto sitting in a browser wallet. They did what they were told. They used the official store.

What this means for you at home and at work

If you run Chrome or Edge, treat every extension as software with access to your browsing life. That is not hype. An extension can see pages, cookies, and in a lot of cases wallet activity. When the payload is built to steal crypto and history, that access is the whole point.

You do not need a dozen add-ons. You need the few you actually use, from developers you can name, with permissions that make sense for the job.

What you should do this week

  • Open your Chrome or Edge extensions page and remove anything you do not recognize or no longer use
  • Be extra careful with anything that asked for permission to read and change data on every website
  • If you keep crypto in a browser wallet, assume a bad extension could have seen it. Move funds from a clean device if anything looks off
  • Do not follow on-screen fix prompts that tell you to paste commands into Run, PowerShell, or Terminal
  • Prefer hardware wallets or dedicated apps over browser extensions for anything you cannot afford to lose

Big tech will tell you the store is safe. The store is a marketplace. Marketplaces get thieves. Keep your house in order, and do not give random add-ons the keys.

Primary Source: https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.