How Malicious Chrome Extensions Are Stealing Crypto Wallets
Not financial advice. For satirical purposes only.
By Jason Jeffries
Imagine a browser extension that arrives dressed like a mild-mannered librarian, promising only to let you copy text or glance at crypto prices. It tips its hat, settles onto the toolbar, and for weeks does exactly what the cheerful store listing claimed. Then one quiet night the librarian sprouts six extra arms, each clutching a different tool, and starts rearranging the furniture while the user scrolls past cat videos. Socket researchers just caught nineteen of these polite houseguests across Chrome and Edge, each carrying a modular malware framework that treats digital wallets like an unsupervised candy jar.
Five of the tools were purchased from their original creators, the online equivalent of buying a neighborhood lemonade stand and swapping the recipe for something that empties pockets. Fourteen more launched looking as innocent as fresh laundry, then auto-updated into something far more ambitious. The headliner, Enable Right Click & Copy — Smart Unlock + OCR, had already collected roughly seventy thousand Chrome users and ten thousand on Edge before the malicious payload arrived. Google eventually noticed and yanked the Chrome version. The Edge store kept the same smiling face on the shelf a little longer, even allowing the operators to change command-and-control addresses mid-performance like a stagehand swapping backdrops between scenes.
Once inside, the framework opens an encrypted WebSocket, downloads fresh JavaScript modules on demand, and goes to work with cartoonish efficiency. One module hijacks legitimate “Connect Wallet” and “Swap” buttons across EVM, Solana, and Tron chains, turning a routine click into an instant transfer. Another replaces real Ledger and Trezor recovery pages with near-perfect fakes designed to vacuum seed phrases. Separate pieces vacuum session tokens and balances from Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. Form fields get recorded. Facebook and LinkedIn accounts get harvested. Browser history packs its bags and leaves. Fake browser-update prompts of the ClickFix variety politely instruct victims to run the attackers’ commands themselves. Socket counted at least nineteen distinct modules, each with its own specialty, all engineered to be swapped or expanded like a toolkit that never stops growing. The whole operation has been simmering since early 2024.
The absurdity sits thick and glossy: store ecosystems that treat every new add-on as a trusted houseguest, automatic updates that arrive without a knock, and users who install first and investigate never. The operators score points for patience and modular greed. The platforms score points for noticing eventually. Anyone who kept these tools installed gets the usual cheerful prescription: assume every credential is compromised, change the passwords, move the crypto to brand-new wallets. The full list of extension IDs is public. Checking it takes less time than reading another breathless store blurb promising convenience. The next clean-looking helper is already waiting in the wings, smiling, ready for its first silent update.
Shark Cage - A SharkBytez Trusted Partner
Are you interested in online trading? Try our trusted platform, Margex — up to 100x leverage on a fast, no-KYC exchange.