19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

August 28, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Chrome and Edge browser users
Incident: Distribution of wallet-stealing malware via malicious browser extension updates.
Impact: Theft of cryptocurrency assets and harvesting of sensitive user data.
Attacker: Superior
Analysis: The ‘Superior’ campaign employs a deceptive lifecycle strategy, publishing clean extensions or purchasing existing ones before pushing malicious updates. By leveraging the default auto-update mechanism of Chrome and Edge, the attackers can deploy wallet-stealing code to an established user base without triggering immediate suspicion. This technique effectively bypasses initial user vetting and exploits the implicit trust in previously installed software.
Recommendations: Conduct a comprehensive audit of all installed browser extensions and remove any that are unnecessary or from unknown developers.; Stay vigilant for extensions requesting excessive permissions, particularly those related to site data or storage.; Utilize a hardware wallet for cryptocurrency assets to isolate private keys from the browser environment.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *