Security News > 2020 > April > 49 malicious Chrome extensions caught pickpocketing crypto wallets

49 malicious Chrome extensions caught pickpocketing crypto wallets
2020-04-16 10:22

Google has kicked 49 malicious Chrome browser extensions out of its Web Store that were posing as cryptocurrency wallets in order to drain the contents of bona fide wallets.

On Tuesday, Harry Denley, MyCrypto Director of Security, said that malicious browser extensions aren't new, but the targets in this campaign are: they include the cryptocurrency wallets Ledger, Trezor, Jaxx, Electrum, MyEtherWallet, MetaMask, Exodus, and KeepKey.

The researchers sent funds to a few addresses and submitted secrets to the malicious extensions.

Although the researchers didn't lose their secrets to the malicious extensions, others have publicly posted about losing funds to the extensions on the Chrome support forum, Reddit and Toshi Times.

Back in February, Google abruptly yanked 500 Chrome extensions off its Web Store after researchers discovered they were stealing browsing data, pulling off click fraud and serving up malvertising.


News URL

https://nakedsecurity.sophos.com/2020/04/16/49-malicious-chrome-extensions-caught-pickpocketing-crypto-wallets/