Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Brief
Socket uncovered a cross-browser extension operation targeting cryptocurrency traders. Four malicious Chrome and Firefox extensions steal authenticated Axiom Trade and Padre session and wallet-related data, while two earlier extensions linked to the same publisher operation reveal a longer-running pattern of repackaging crypto trading tools.
The Socket Threat Research team identified six Chrome and Firefox extensions linked through a combination of shared code, command and control (C2) infrastructure, publishing history, cloned crypto trading tools, marketplace artifacts, and specific targeting of Axiom Trade and Padre (now Terminal) users.
The Chrome extensions J7Tracker and VREO , and the Firefox version of VREO , contain the same malicious Axiom and Padre collection module . The module is byte-identical across all three analyzed extensions.
