Security News > 2022 > November > Google Chrome extension used to steal cryptocurrency, passwords

Google Chrome extension used to steal cryptocurrency, passwords
2022-11-21 18:24

An information-stealing Google Chrome browser extension named 'VenomSoftX' is being deployed by Windows malware to steal cryptocurrency and clipboard contents as users browse the web.

This Chrome extension is being installed by the ViperSoftX Windows malware, which acts as a JavaScript-based RAT and cryptocurrency hijacker.

To stay hidden from the victims, the installed extension masquerades as "Google Sheets 2.1", supposedly a Google productivity app.

The extension can modify HTML on websites to display a user's cryptocurrency wallet address while manipulating the elements in the background to redirect payments to the threat actor.

Info, the extension will also attempt to steal passwords entered on the site.

As Google Sheets is normally installed in Google Chrome as an app under chrome://apps/and not an extension, you can check your browser's extension page to determine if Google Sheets is installed.


News URL

https://www.bleepingcomputer.com/news/security/google-chrome-extension-used-to-steal-cryptocurrency-passwords/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 995 4853 2786 1619 10253