19 Chrome and Edge Extensions Discovered with Wallet‑Stealing and Crypto‑Draining Code
What Happened — Researchers identified 18 malicious Google Chrome extensions and one Microsoft Edge extension that were published to official stores over the past six months. The extensions contain code that silently harvests cryptocurrency wallet credentials and initiates unauthorized transfers.
Why It Matters for Compliance & Audit Readiness
- This campaign exemplifies a failure of access‑control policies and software‑supply‑chain vetting that SOC 2 expects organizations to enforce for all endpoint tools.
- Continuous monitoring of approved browser extensions and evidence of policy enforcement are core audit artifacts for the CC6 – System and Communications Protection and CC7 – System Operations criteria.
- Demonstrating a documented security‑awareness program that warns users against installing unverified extensions helps satisfy the CC3 – Risk Management control family.
Who Is Affected – Any organization whose employees use Chrome or Edge for work, spanning technology, finance, healthcare, and retail sectors.
Recommended Actions
- Inventory all browser extensions in use and cross‑reference against an approved‑list baseline.
- Enforce a policy that blocks installation of extensions not vetted through a secure approval workflow.
- Deploy endpoint‑management tools that log extension install/uninstall events for continuous audit evidence.
- Conduct security‑awareness training that highlights the risk of malicious extensions and how to verify publisher legitimacy.
Technical Notes – The extensions share obfuscated JavaScript that injects a wallet‑address scraper and calls public blockchain APIs to move funds. No CVE is associated; the threat vector is malicious supply‑chain code delivered via official browser stores. Source: The Hacker News