We detected 7 dynamic runtime impersonating malicious Chrome extensions. A remote kill-switch tar...
7 malicious Chrome extensions impersonating crypto wallets detected with Unicode spoofing and remote kill-switch.
Run Chrome?
Get an email when a reviewed story names Chrome, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Security researchers discovered 7 dynamic runtime malicious Chrome extensions targeting cryptocurrency users through deceptive practices including Unicode BIDI spoofing, dual-identity tactics, and fake wallet drainers. The extensions impersonate legitimate wallets like Ledger, Braavos, and Solana, and feature a remote kill-switch mechanism. This campaign represents a sophisticated supply-chain attack leveraging browser extensions to compromise crypto asset security.
Indicators of Compromise
- malware — Chrome Extension BSC Drainer
- malware — Fake Solana Wallet Extension
- mitre_attack — T1036.005
- mitre_attack — T1566.002