19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads
Brief
Socket identified 19 malicious extensions published in the last six months, delivering an extendable malware framework. Identified malware samples create WebSocket communication channel with command and control (C2) server, perform CSP stripping and abuse XSS injection to trigger execution of malicious payloads previously downloaded from the C2 server.
Malicious capabilities are primarily focused on, but not limited to, wallet secret stealing and crypto draining. The most impactful tactic is acquisition of established extensions offered for sale with an existing user base, which then get weaponized with malicious functionality.
The Socket Threat Research team identified 18 Chrome extensions and 1 Edge extension sharing similarities in malicious code and malware operation techniques.
