Threat Intelligence

Fake Browser Extensions Caught Stealing Crypto Wallet Data and Login Tokens

The Hacker News · 11 Sept 2026
Key Takeaway Regularly audit installed browser extensions, remove unused or unverified ones, and limit the permissions granted to any extension used by staff.

Security researchers have identified four malicious browser extensions, J7Tracker, VREO and Orbit Tracker, that target users of the Axiom Trade and Padre trading platforms. The extensions are designed to steal session tokens, wallet-related data and authentication tokens, sending the stolen information to servers controlled by the attackers.

According to researchers at Socket, three of the four extensions share an identical malicious code module, suggesting a coordinated campaign rather than isolated incidents. The same publisher behind these tools has previously been linked to other fake extensions, including one impersonating a legitimate trading add-on called MockApe. This pattern shows attackers reusing proven tricks and code across multiple disguises to maximise their reach.

While this campaign targets crypto trading users specifically, it highlights a broader risk for any business relying on browser extensions for productivity or finance tools: extensions can request broad permissions and quietly exfiltrate sensitive data long after installation.

Key Takeaway: Australian small businesses should regularly audit installed browser extensions, remove any that are unused or unverified, and avoid granting extensions more access than their function requires.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.