Fake Browser Extensions Caught Stealing Crypto Wallet Data and Login Tokens
Security researchers have identified four malicious browser extensions, J7Tracker, VREO and Orbit Tracker, that target users of the Axiom Trade and Padre trading platforms. The extensions are designed to steal session tokens, wallet-related data and authentication tokens, sending the stolen information to servers controlled by the attackers.
According to researchers at Socket, three of the four extensions share an identical malicious code module, suggesting a coordinated campaign rather than isolated incidents. The same publisher behind these tools has previously been linked to other fake extensions, including one impersonating a legitimate trading add-on called MockApe. This pattern shows attackers reusing proven tricks and code across multiple disguises to maximise their reach.
While this campaign targets crypto trading users specifically, it highlights a broader risk for any business relying on browser extensions for productivity or finance tools: extensions can request broad permissions and quietly exfiltrate sensitive data long after installation.
Key Takeaway: Australian small businesses should regularly audit installed browser extensions, remove any that are unused or unverified, and avoid granting extensions more access than their function requires.