Security researchers have discovered that the latest version of the MEGA Google Chrome extension is stealing login credentials and security keys from crypto wallets. Once it was discovered that the original application had been replaced with a similar, but infected one, Google removed the extension from the Chrome Web Store.

The hacked extension was discovered by SerHack, a security researcher and volunteer on the Monero project, who immediately tweeted his finding, warning that version 3.39.4 of the MEGA Chrome extension has been infected.
Once installed, the infected extension checks whether the user fills out forms with login details from Google , Amazon, Microsoft, and Github services , in order to record them.
In addition to these 4 services, it can also detect Login forms from different platforms through specific Patterns. The code checks the page URL to see if it contains common words that would be contained in a Login URL, such as “username”, “email”, “user”, “login”, “usr”, “pass”, “passwd”, or “password”.
If the extension detects a Login form, it records the data and later sends it to a host in Ukraine named www.megaopac.host.
But there's something worse. Among the sites it automatically checked were cloud crypto wallets like myetherwallet, mymonero, and Idex.market. If it detected them, it would run malicious JavaScript code that attempted to steal the private keys of the logged-in user.
According to the Chrome extension archive site, crx.dam.io, the last version released was 3.39.3 on September 2, 2018, and its code was secure.
If you were one of the users using this extension, we recommend that you immediately change the passwords of your online accounts.
