Researchers observed a massive campaign pushing fake browser extensions onto users – including among them Google Chrome extensions – , which mimic popular brands using Google Ads and other advertising channels.
The extensions aim to steal mnemonic phrases, private keys , and Keystore files from users and send them to the attacker's server.

49 Chrome extensions were identified
The malicious encryption extensions were discovered by Harry Denley, Security Director at the MyCrypto platform. They impersonate popular brands such as Trezor, Jaxx, Electrum, MyEtherWallet, MetaMask, Exodus, and KeepKey.
As soon as the user enters secret keys with these fake extensions, the extensions then send an HTTP POST request to the C2 server controlled by the attacker.
The researchers also showed a video about how the extension targets the user’s work of MyEtherWallet. It asks users to enter all the details and the interface resembles that of MyEtherWallet itself.
Once the user enters the details, the secret information sent to the server is monitored by attackers.
Most of the C2 servers were found to have been registered between March and April 2020, the oldest among them is (ledger.productions).
Some of the extensions use phishing data in a GoogleDocs form and some of the malicious extensions use their PHP scripts, the researchers reported.
“Some of the extensions had a network of fake users who rated the app 5 stars and gave positive comments about the extension to entice a user to download it. Most of the positive comments from the fake users were of low quality, such as “good”, “useful app” or “legitimate extension.”
All malicious extensions were reported by the researchers to the Google Webstore and were removed within 24 hours.
“An analysis of our data set shows that malicious extensions were slowly rolling out in February 2020, increased their releases through March 2020, and then in April 2020 they significantly increased their releases,” said Harry Denley.
The attackers who abuse the Chrome store are not new, recently 500+ malicious Chrome extensions were removed from the official Chrome Web Store.
