Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
ID: 7bbba346-903c-55bf-b3bf-80864d0330c8
STIX ID: report--7bbba346-903c-55bf-b3bf-80864d0330c8
Feed Name: GBHackers
Socket researchers identified 19 malicious browser extensions (18 Chrome, 1 Edge) that employ a modular, encrypted C2-driven framework to strip Content Security Policy headers, inject attacker-controlled JavaScript into page contexts, and download modules that steal cryptocurrency wallets, session tokens, cookies, credentials, and other sensitive data; the extensions affected roughly 80,000 installs in total, used AES-GCM and encrypted WebSocket channels with C2 rotation, and relied on dynamic script injection and DOM-event techniques to execute in the page’s main world—Chrome removed the listing but an Edge build remained active at publication with fresh C2 domains; the report includes technical TTPs, observed modules (multi-chain wallet drainer, fake update workflows), mitigation recommendations, and a list of domain IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
