Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Chrome Web Store Extensions Hijacked to Steal Crypto and Browser Data

Researchers discovered 19 Chrome/Edge extensions that were turned malicious after initial release, stealing cryptocurrency wallets, browser history and login tokens. The incident underscores the need for continuous third‑party monitoring and auditable evidence of vendor oversight for compliance readiness.

LiveThreat™ Intelligence · 📅 August 30, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

Chrome Web Store Extensions Hijacked to Steal Crypto and Browser Data

What Happened – Researchers at Socket uncovered a malicious framework hidden in 19 Chrome and Edge extensions. The extensions initially appeared benign, but later updates injected code that harvested cryptocurrency wallets, browser history, login tokens and even forged phishing pages for Ledger/Trezor sites. Google removed the affected Chrome extensions; the Edge versions remained publicly reachable at the time of reporting.

Why It Matters for Trust & Control Assurance

  • The campaign illustrates how a trusted software marketplace can become a conduit for supply‑chain compromise, a scenario continuous control‑assurance programs are built to detect and document.
  • Maintaining auditable evidence of third‑party vetting, version‑control monitoring, and rapid remediation directly mitigates the risk shown here.
  • Leveraging Verisq’s Vendor Risk Management capability provides a single source of truth for extension provenance, update‑change logs, and real‑time compliance posture.

Who Is Affected – End‑user browsers across all sectors (technology, finance, healthcare, retail, etc.) that install extensions from public stores; organizations that rely on employee browsers for corporate access.

Recommended Actions

  • Inventory all browser extensions in use across your enterprise and map them to a vendor‑risk register.
  • Enable continuous monitoring of extension metadata (publisher, version, permissions) and set alerts for sudden changes or removal from official stores.
  • Apply a strict allow‑list policy for extensions, and enforce multi‑factor authentication for any wallet‑related web activity.
  • Document the review process and evidence in your Trust Center to demonstrate due diligence during audits.

Technical Notes – The malware establishes an encrypted WebSocket C2 channel, strips CSP headers, injects malicious scripts, and hijacks “Connect Wallet” buttons on popular crypto sites. Modules also harvest credentials from Coinbase, Binance, Kraken, MetaMask, and social platforms (Facebook, LinkedIn). The campaign has been active since early 2024 and may evolve with new payloads. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →