← Terug naar overzicht

Cybersecurity researchers at Socket discovered 18 Google Chrome and 1 Microsoft Edge malicious browser extensions published over the last six months. These extensions contain wallet secret-stealing and cryptocurrency-draining capabilities. Researcher Karlo Zanki found that the extensions share similarities in code and tradecraft, suggesting a coordinated campaign. The extensions appear to have been part of an active and deliberate attack campaign targeting cryptocurrency users. The malicious extensions were distributed through official browser extension stores, posing significant risk to users who installed them. The campaign highlights ongoing threats to cryptocurrency holders through supply chain and browser-based attack vectors.

Technical details

A cluster of 18 Google Chrome and 1 Microsoft Edge malicious extensions, tracked as 'Superior' by Socket, were discovered harboring wallet-secret stealing and cryptocurrency draining capabilities. The campaign has been active since at least February 2024. The threat actor either acquires legitimate extensions from their original owners or publishes clean versions to gain user downloads, then releases an updated version containing malicious code. 14 extensions were created by the threat actor and 5 were purchased from original owners. The most impactful extension ('Enable Right Click & Copy — Smart Unlock + OCR') has ~80,000 installs. The malicious code strips Content Security Policy (CSP) headers from every page and injects JavaScript modules via content scripts. Extensions establish persistent WebSocket connections to C2 servers, support C2 endpoint rotation to evade detection, and use dynamically received per-victim data exfiltration endpoints. 16 malicious modules were identified spanning: multi-chain wallet drainer, hardware-wallet seed-phrase harvester, cryptocurrency exchange/wallet account harvester, universal credential/form grabber, Facebook and LinkedIn account stealers, browser history stealer, and a ClickFix-style lure. The ClickFix module injects a fake browser update prompt with OS-specific instructions to get users to copy-paste malicious commands. Chrome's default auto-update mechanism is exploited to automatically push malicious updates to users.

Mitigation steps

1. Immediately remove any of the 19 identified malicious extensions from Chrome and Edge browsers using the listed extension IDs. 2. Check browser extension lists against the provided extension IDs and names to identify if any are installed. 3. If any of these extensions were installed, treat all stored credentials, cryptocurrency wallet seeds, and browser history as potentially compromised — rotate passwords, revoke wallet access, and move crypto assets to new wallets. 4. Monitor for suspicious WebSocket connections originating from browser processes to unknown C2 servers. 5. Audit browser extension policies within organizations to restrict installation to approved extensions only. 6. Disable or manage Chrome/Edge auto-update settings for extensions in enterprise environments to prevent silent malicious updates. 7. Implement browser security policies (e.g., via enterprise MDM) that enforce extension allowlisting. 8. Educate users to be cautious about installing browser extensions, especially those related to cryptocurrency, SEO, or productivity tools from unverified publishers. 9. Monitor for ClickFix-style clipboard injection attacks where fake browser update prompts instruct users to paste commands. 10. Review the Socket blog's Indicators of Compromise page for additional technical indicators and network IOCs.

Affected products

  • Google Chrome (extensions: Blockfolio: Address Monitor [ahpnnnjbnfbhoikhohglpohnoocjcoco])
  • Google Chrome (extensions: Creative Library - Ad Spy Tool [cfpnjdbpojpcongfaefcamjbaolpelcd])
  • Google Chrome (extensions: Crypto Alerter: Price Alarms & Volatility Warnings [jmlgannjlbliikgcaieomgmcnfplglea])
  • Google Chrome (extensions: Crypto Price Badge: Quick Glance [gfackggoapepdmnjnkblogdcjpgcjiak])
  • Google Chrome (extensions: Crypto Rates & Fiat Converter [oeacadlaclegkkkdehjmiifnjhcekclj])
  • Google Chrome (extensions: DeFi Pulse Tracker [lhmcajhgadanidbopgaoobjlldegjmke])
  • Google Chrome (extensions: Enable Right Click & Copy — Smart Unlock + OCR [koccklolohdacbfooifnpebakpbeipc])
  • Google Chrome (extensions: LedgerLook: Wallet Checker [cngchfbfgejllcbhmeadjhiebebiome])
  • Google Chrome (extensions: Meta & Facebook Ad Library Spy — FeedX-Ray [aodkjdeghbjiaienipfjkbpcikkacbcp])
  • Google Chrome (extensions: Multi-Chain Explorer [hfijkbdkpidafdbeebnnkhfccildbcle])
  • Google Chrome (extensions: Password Protect PDF [jamminefolhgepgihbmcjjhgldbfcikp])
  • Google Chrome (extensions: PixelCheck [fcgdejjichpgfaaafflplhfijcnieopb])
  • Google Chrome (extensions: Private Crypto News Reader [iekoapohahgmogbagegmcgplbkikcgke])
  • Google Chrome (extensions: QuickLens - Search Screen with Google Lens [kdenlnncndfnhkognokgfpabgkgehodd])
  • Google Chrome (extensions: RapidLens - Google Lens for Screen Search & Images [fegckejpfnlmfgkfjpinlbgmeeijjkel])
  • Google Chrome (extensions: SEO Pulse Pro - Website Traffic & SEO Analyzer [fjmlhlkccegopebcllcmafahkmeejpph])
  • Google Chrome (extensions: Site Signal - Website Traffic & SEO Checker [dkdadldmiefjldmegbjbnhhfddnkhlhm])
  • Google Chrome (extensions: Website Traffic Checker: MirrorSphere SEO Stats [aapdalkmclfaahehnmicbglkohkldhne])
  • Microsoft Edge (extensions: Allow Copy - Select & Enable Right Click [inmkjedjdhgpknjogbjomhnbgdccckkg])

Related threat actors

  • Superior (tracked by Socket)

IOC's

Extension ID: koccklolohdacbfooifnpebakpbeipc (Enable Right Click & Copy — Smart Unlock + OCR), Extension ID: fegckejpfnlmfgkfjpinlbgmeeijjkel (RapidLens - Google Lens for Screen Search & Images), Extension ID: kdenlnncndfnhkognokgfpabgkgehodd (QuickLens - Search Screen with Google Lens), Extension ID: jamminefolhgepgihbmcjjhgldbfcikp (Password Protect PDF), Extension ID: inmkjedjdhgpknjogbjomhnbgdccckkg (Allow Copy - Select & Enable Right Click), Extension ID: fcgdejjichpgfaaafflplhfijcnieopb (PixelCheck), Extension ID: cfpnjdbpojpcongfaefcamjbaolpelcd (Creative Library - Ad Spy Tool), Extension ID: aapdalkmclfaahehnmicbglkohkldhne (Website Traffic Checker: MirrorSphere SEO Stats), Extension ID: dkdadldmiefjldmegbjbnhhfddnkhlhm (Site Signal - Website Traffic & SEO Checker), Extension ID: fjmlhlkccegopebcllcmafahkmeejpph (SEO Pulse Pro - Website Traffic & SEO Analyzer), Extension ID: iekoapohahgmogbagegmcgplbkikcgke (Private Crypto News Reader), Extension ID: ahpnnnjbnfbhoikhohglpohnoocjcoco (Blockfolio: Address Monitor), Extension ID: oeacadlaclegkkkdehjmiifnjhcekclj (Crypto Rates & Fiat Converter), Extension ID: jmlgannjlbliikgcaieomgmcnfplglea (Crypto Alerter: Price Alarms & Volatility Warnings), Extension ID: lhmcajhgadanidbopgaoobjlldegjmke (DeFi Pulse Tracker), Extension ID: gfackggoapepdmnjnkblogdcjpgcjiak (Crypto Price Badge: Quick Glance), Extension ID: hfijkbdkpidafdbeebnnkhfccildbcle (Multi-Chain Explorer), Extension ID: cngchfbfgejllcbhmeadjhiebebiome (LedgerLook: Wallet Checker), Extension ID: aodkjdeghbjiaienipfjkbpcikkacbcp (Meta & Facebook Ad Library Spy — FeedX-Ray), Persistent WebSocket connections to C2 servers from browser extensions, CSP header stripping on visited web pages, Injection of JavaScript modules via content scripts, Dynamic C2 endpoint rotation behavior

Categories

  • Data Breach & Exfiltration
  • Ransomware & Malware
  • Supply Chain & Dependencies
  • Web Technologies