
Security researchers have discovered a group of Chrome extensions that were injected with malware and were capable of stealing people’s sensitive data, though each extension has now been de-listed from the Chrome Web Store, with Google having acted on one of them early on. The extensions, of which there were 19 in total, were running an operation that allowed them to steal crypto from crypto wallets as well as sensitive data like passwords and other personal information. The operation of these extensions was discovered by security research firm Socket, which published its findings on the extensions back on August 27.
All the malicious extensions have since been pulled from the Chrome Web Store. However, these extensions could still be a threat to anyone that still has them installed or had them installed at one point. Users who may have had them installed should operate under the assumption that their personal data, such as passwords, was compromised, and work through changing all their passwords.
The Chrome extension malware operation was capable harvesting Facebook and LinkedIn information
According to the report, the group of extensions would inject malware modules that were capable of draining crypto wallets containing Solana, Tron, and EVM, while also harvesting information from Facebook and LinkedIn. They were also capable of recording credentials and entries from across websites and grabbing browser history.
The list of extensions includes: Enable Right Click & Copy — Smart Unlock + OCR, RapidLens – Google Lens for Screen Search & Images, QuickLens – Search Screen with Google Lens, Password Protect PDF, Allow Copy – Select & Enable Right Click (Edge extension), PixelCheck, Creative Library – Ad Spy Tool, Website Traffic Checker: MirrorSphere, Site Signal – Website Traffic & SEO, SEO Pulse Pro – Website Traffic & SEO, Private Crypto News Reader, Blockfolio: Address Monitor, Crypto Rates & Fiat Converter, Crypto Alerter: Price Alarms & Volatility Warnings, DeFi Pulse Tracker, Crypto Price Badge: Quick Glance, Multi-Chain Explorer, LedgerLook: Wallet Checker, and Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray.
Out of the extensions listed, Enable Right Click & Copy — Smart Unlock + OCR, RapidLens – Google Lens for Screen Search & Images, QuickLens – Search Screen with Google Lens, Password Protect PDF, and Allow Copy – Select & Enable Right Click were all created by genuine extension developers, but were purchased at some point by the threat actors. The remaining extensions were all created by the threat actors with the intent to steal crypto and sensitive data.
The post 19 Chrome extensions were discovered to be crypto-stealing malware appeared first on Android Headlines.
​Â