[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFeX5XmJ2ydZUlPkcHMpq1W6sIGuSqqCAp9OzyZk0qiY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"e5fb468c-cf1e-40bc-96bd-08919b98cf8e","malicious-browser-extensions-hijack-crypto-wallets-and-steal-user-data","633cf94a-3a25-4566-a315-c483b1f07a01","Malicious Browser Extensions Hijack Crypto Wallets and Steal User Data","Attackers compromised legitimate browser extensions by injecting malicious code through trusted update mechanisms, effectively weaponizing software users already trusted. This is a classic supply chain attack — the threat entered through a legitimate, often overlooked channel rather than a direct exploit. The fact that Edge's store still hosted the malicious extensions after Google acted highlights inconsistent enforcement across platforms. Users are conditioned to trust installed extensions and automatic updates, making this vector particularly dangerous for stealing high-value assets like cryptocurrency.","**Immediate actions:**\n- Audit all installed browser extensions across your organization and remove any that are unverified, unused, or recently flagged by threat intelligence feeds.\n- Force-remove or blocklist the identified malicious extensions using endpoint management tools (e.g., Group Policy, MDM) before users can interact with them.\n\n**Long-term improvements:**\n- Establish an approved allowlist of permitted browser extensions and enforce it via browser policy across all managed devices.\n- Implement a browser extension vetting process that reviews permissions, publisher reputation, and update history before approving new extensions.\n- Separate high-value activities such as cryptocurrency transactions onto dedicated, locked-down devices or browser profiles with minimal extensions installed.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tooling capable of flagging anomalous browser extension behavior, such as unexpected DOM access or outbound data exfiltration.\n- Monitor network traffic for connections to known malicious domains associated with credential-stealing or crypto-draining campaigns.\n- Subscribe to browser vendor security bulletins and threat intelligence feeds to receive timely alerts about newly identified malicious extensions.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SA-12: Supply Chain Protection","NIST CSF PR.DS-5: Protections Against Data Leaks","GDPR Article 32: Security of Processing","ITIL: Change and Release Management (vetting software updates)","published","2026-08-30T16:20:49.32848+00:00","2026-08-30T16:20:49.251+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchrome-web-store-extensions-caught-stealing-crypto-browser-data\u002F","chrome-web-store-extensions-caught-stealing-crypto-browser-data-e972cc","Chrome Web Store extensions caught stealing crypto, browser data",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"7954e6c6-5e7e-4f15-82df-c49747e2b3f0","2026-08-31","morning","ThreatNoir Morning Brief — August 31","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-31\u002Fthreatnoir-morning-brief-2026-08-31.mp3"]