Chrome Web Store extensions caught stealing crypto, browser data

Summary

Multiple extensions available on the Chrome Web Store have been found to contain a malware framework. This framework deploys modules designed to steal cryptocurrency, sensitive user data, and browser history, and also injects deceptive 'ClickFix' lures.

IFF Assessment

FOE

This article details malicious browser extensions designed to steal user data and cryptocurrency, representing a direct threat to individuals and their digital assets.

Defender Context

This incident highlights the ongoing risk posed by malicious browser extensions and the importance of vigilant security practices for users. Defenders should be aware of such threats and advise users to carefully vet extensions before installation, check permissions, and regularly review installed extensions for suspicious activity.

Read Full Story →