logo

Malicious Chrome Extension Steals Wallet Login Credentials and Enables Automated Trading

ID: 71bf8a17-5f03-52b8-bf36-06a24c08dd0d

STIX ID: report--71bf8a17-5f03-52b8-bf36-06a24c08dd0d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious Chrome extension named 'MEXC API Automator' distributed via the Chrome Web Store automatically enables withdrawal permissions when users create API keys on MEXC, visually hides that change via CSS and MutationObservers, scrapes newly created Access and Secret keys from the success modal, and silently exfiltrates them to a hardcoded Telegram bot and chat ID—enabling account takeover and fund theft; Socket.dev researchers flagged the extension as malware and linked it to actor 'jorjortan142'.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.