Chrome Web Store Extensions Hijacked to Steal Crypto and Browser Data
What Happened – Researchers at Socket uncovered a malicious framework hidden in 19 Chrome and Edge extensions. The extensions initially appeared benign, but later updates injected code that harvested cryptocurrency wallets, browser history, login tokens and even forged phishing pages for Ledger/Trezor sites. Google removed the affected Chrome extensions; the Edge versions remained publicly reachable at the time of reporting.
Why It Matters for Trust & Control Assurance
- The campaign illustrates how a trusted software marketplace can become a conduit for supply‑chain compromise, a scenario continuous control‑assurance programs are built to detect and document.
- Maintaining auditable evidence of third‑party vetting, version‑control monitoring, and rapid remediation directly mitigates the risk shown here.
- Leveraging Verisq’s Vendor Risk Management capability provides a single source of truth for extension provenance, update‑change logs, and real‑time compliance posture.
Who Is Affected – End‑user browsers across all sectors (technology, finance, healthcare, retail, etc.) that install extensions from public stores; organizations that rely on employee browsers for corporate access.
Recommended Actions
- Inventory all browser extensions in use across your enterprise and map them to a vendor‑risk register.
- Enable continuous monitoring of extension metadata (publisher, version, permissions) and set alerts for sudden changes or removal from official stores.
- Apply a strict allow‑list policy for extensions, and enforce multi‑factor authentication for any wallet‑related web activity.
- Document the review process and evidence in your Trust Center to demonstrate due diligence during audits.
Technical Notes – The malware establishes an encrypted WebSocket C2 channel, strips CSP headers, injects malicious scripts, and hijacks “Connect Wallet” buttons on popular crypto sites. Modules also harvest credentials from Coinbase, Binance, Kraken, MetaMask, and social platforms (Facebook, LinkedIn). The campaign has been active since early 2024 and may evolve with new payloads. Source: BleepingComputer