highSupply Chain

Malicious Chrome/Edge Extensions Wallet-Stealing and Crypto-Draining Campaign

First seen Aug 31, 2026 · Updated Aug 31, 2026

browser-extensioncryptocurrency-theftmalicious-extensionchromeedgewallet-stealeragent-relevant

Researchers identified 19 malicious Chrome and Edge extensions published over the past six months that steal cryptocurrency wallet secrets and drain funds. The extensions share common code and tradecraft, suggesting a coordinated campaign distributed through official browser extension stores. This poses a broad supply-chain risk to any user or organization installing these extensions.

Technical Analysis

The malicious extensions were published to the Chrome Web Store and Microsoft Edge Add-ons store, evading vetting processes and remaining live for up to six months. They contain code designed to intercept and exfiltrate cryptocurrency wallet secrets (private keys, seed phrases) and manipulate transaction data to drain funds from browser-based wallets such as MetaMask. Code similarity analysis by Socket researcher Karlo Zanki indicates a shared toolkit or single threat actor group behind the cluster, likely using obfuscation and delayed activation to bypass automated store review. Organizations running browser-based AI agent tools, autonomous web-browsing agents, or agents with access to crypto wallets or API keys stored in browser extension storage could have those credentials harvested if compromised extensions are installed in the same browser profile, extending the attack's impact beyond individual users to automated agent workflows.

Affected Systems

Google Chrome browser (any version supporting Manifest V2/V3 extensions), Microsoft Edge browser, systems with cryptocurrency wallet browser extensions (e.g., MetaMask) installed, users who installed any of the 19 identified malicious extensions in the last six months

Indicators of Compromise

  • 18 unidentified Chrome Web Store extension listings (specific IDs not disclosed in source)
  • 1 unidentified Microsoft Edge Add-ons extension listing
  • Associated C2 domains not disclosed in available data
  • Refer to Socket security research report for full extension names/IDs and hashes

Remediation Steps

  1. 1

    Audit installed extensions

    Review all browser extensions installed across the organization, especially those with wallet or financial permissions, and remove any unrecognized or unnecessary extensions.

  2. 2

    Cross-reference with Socket's disclosed IOC list

    Obtain the full list of 19 malicious extension names/IDs from the Socket security report and check enterprise browser fleets for their presence.

  3. 3

    Rotate exposed credentials and wallet keys

    If any of the identified extensions were installed, treat associated wallet seed phrases, private keys, and any stored API keys or session tokens as compromised and rotate/migrate them immediately.

  4. 4

    Enforce extension allowlisting

    Deploy browser management policies (Chrome Enterprise, Edge for Business) to restrict extension installs to a vetted allowlist.

  5. 5

    Monitor for anomalous wallet/API activity

    Watch for unauthorized transactions or unusual API key usage, particularly for systems where AI agents or automation tools share browser profiles with compromised extensions.

Industries Most Exposed

cryptocurrencyfinancetechnologyretailgeneral consumer

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.