Cybersecurity researchers at Socket identified 19 malicious browser extensions across Google Chrome and Microsoft Edge that steal wallet secrets and drain cryptocurrency holdings. The cluster, discovered across the past six months, shares code similarities and execution patterns suggesting coordinated campaign activity.

Karlo Zanki, security researcher at Socket, documented the threat group's consistent tradecraft across all samples. The extensions exploit the browser's privileged access to user data and web interactions. Once installed, they target wallet applications and cryptocurrency platforms by harvesting private keys, seed phrases, and authentication credentials.

Browser extensions operate with elevated permissions that desktop applications cannot obtain. Users grant these permissions during installation, often without fully understanding the scope. Attackers leverage this trust model to position malware adjacent to sensitive financial activity. The extensions can intercept clipboard data, monitor network traffic, modify page content, and access stored credentials.

The 18 Chrome extensions and single Edge extension followed similar distribution patterns. Threat actors published them to official app stores using varied names to evade detection filters. This approach differs from malware delivered through phishing or drive-by downloads. Official store distribution creates false legitimacy and reduces initial suspicion from potential victims.

The campaign targets users holding cryptocurrency or managing digital wallets. Victims likely downloaded extensions believing they offered utility functions like portfolio tracking, exchange integrations, or security enhancements. Once activated, the malicious code executed wallet draining operations without user awareness. The code pattern similarities suggest the same developer or organized group deployed multiple instances across both browser platforms.

Google removed the Chrome extensions from its Web Store following researcher disclosure. Microsoft took similar action with the Edge extension. However, users who installed these extensions before removal require manual intervention. The extensions persist on infected systems unless explicitly deleted from browser extension settings.

Organizations face layered risk from this campaign. Employees using personal browsers for cryptocurrency trading or blockchain projects can introduce wallet-draining malware into home networks and corporate devices. Financial services companies, cryptocurrency exchanges, and blockchain platforms represent secondary targets if employee credentials become compromised. The stolen wallet secrets could fund further attacks or finance organized crime operations.

Individual risk remains direct and severe. A compromised wallet seed phrase allows attackers permanent theft of all funds, regardless of subsequent password changes or security updates. Victims discovering compromised wallets often face irreversible loss. Blockchain transactions execute immutably, making fund recovery impossible without law enforcement intervention in rare circumstances.

The campaign illustrates persistent vulnerabilities in app store curation systems. Malware authors register disposable developer accounts, publish extensions under generic names, and disappear after installation targets reach sufficient numbers. Store operators employ automated scanning and manual review, but determined attackers repeatedly find gaps. The six-month active period suggests the operation remained undetected through multiple review cycles.

Users should audit installed extensions immediately. Chrome users navigate to chrome://extensions and review each extension's permissions and publisher details. Edge users access edge://extensions for the same purpose. Removing unfamiliar extensions or those from unknown publishers eliminates basic risk. Users holding significant cryptocurrency should isolate wallet management to dedicated, air-gapped devices or hardware wallets that never connect to potentially compromised systems.