Chrome Web Store extensions caught stealing crypto, browser data
Summary
Multiple extensions available on the Chrome Web Store have been found to contain a malware framework. This framework deploys modules designed to steal cryptocurrency, sensitive user data, and browser history, and also injects deceptive 'ClickFix' lures.
IFF Assessment
This article details malicious browser extensions designed to steal user data and cryptocurrency, representing a direct threat to individuals and their digital assets.
Defender Context
This incident highlights the ongoing risk posed by malicious browser extensions and the importance of vigilant security practices for users. Defenders should be aware of such threats and advise users to carefully vet extensions before installation, check permissions, and regularly review installed extensions for suspicious activity.