Security News > 2020 > May > More crypto-stealing Chrome extensions swatted by Google

More crypto-stealing Chrome extensions swatted by Google
2020-05-08 10:15

Google deleted 49 malicious Chrome extensions from the Chrome Web Store in mid-April after Harry Denley, director of security at MyCrypto, found them phishing cryptocurrency users.

The extensions impersonate Chrome extensions for legitimate cryptocurrency wallets, but when installed they pilfer the users' private keys and other secrets used to access digital wallets so that their authors can steal victims' funds.

Google has acknowledged a general problem with malicious extensions and has announced new rules for the Chrome Web Store.

The problem, according to Dan Finlay, the lead developer at crypto wallet company MetaMask, is that Google allows phishing ads that point to fake extensions.

The official MetaMask extension has over 1,000,000 users - you'd assume Google would have some sort of plan to tackle any potential fake extensions with the Metamask branding.


News URL

https://nakedsecurity.sophos.com/2020/05/08/more-crypto-stealing-chrome-extensions-swatted-by-google/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 996 4899 2857 1622 10374