logo

Malicious Chrome Extension Drains Crypto via Secret API Keys

ID: dfed65c3-8ad8-5343-83de-e901b63255cb

STIX ID: report--dfed65c3-8ad8-5343-83de-e901b63255cb

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Socket’s Threat Research Team identified a malicious Chrome extension, “MEXC API Automator,” published on the Chrome Web Store that silently creates MEXC API keys with withdrawals enabled, masks the withdrawal permission in the UI, and exfiltrates the API key and secret to a hardcoded Telegram bot—allowing attackers to drain users’ accounts; code comments suggest a Russian-speaking actor linked to a broader SwapSushi-themed crypto theft campaign and Google has been notified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.