Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Socket uncovered a cross-browser extension campaign using malicious Chrome and Firefox add-ons to steal authenticated Axiom Trade and Padre session data, wallet-related state, tokens, and cookies from cryptocurrency traders. The operation spans J7Tracker, VREO, Orbit Tracker, GhostApe, and GhostApe Color, with exfiltration sent to threat actor-controlled Vercel and other infrastructure. #J7Tracker #VREO #OrbitTracker #GhostApe #AxiomTrade #Padre #Vercel

Keypoints

  • Socket identified six malicious Chrome and Firefox extensions linked by shared code, infrastructure, and publishing history.
  • J7Tracker, VREO, and Firefox VREO used a byte-identical module to collect authenticated Axiom and Padre session and wallet data.
  • Orbit Tracker used different malicious logic and C2 infrastructure but targeted the same Axiom users and wallet-related data.
  • GhostApe and GhostApe Color appear to be earlier repackaged crypto-trading extensions tied to the same publisher portfolio.
  • Stolen data included access tokens, cookies, user information, bundles, and local browser-stored session material, then was Base64-encoded and exfiltrated.
  • The campaign targeted high-volume trading communities, including Axiom and Padre users, and remained active across Chrome and Firefox marketplaces.
  • Defenders were advised to block the extension IDs, revoke sessions and tokens, hunt the listed infrastructure, and restrict extensions in sensitive browser profiles.

MITRE Techniques

  • [T1176.001 ] Software Extensions: Browser Extensions – The attack was delivered through malicious browser add-ons installed in Chrome and Firefox. (‘malicious Chrome and Firefox extensions’)
  • [T1036 ] Masquerading – The extensions masqueraded as legitimate crypto trading tools and repackaged existing products. (‘repackaging crypto trading tools’, ‘brandjacking derivative’)
  • [T1204 ] User Execution – The malware relied on victims installing and using the extension in their browser. (‘Once the targeted trading platform is open… the collector runs inside the authenticated session’)
  • [T1059.007 ] Command and Scripting Interpreter: JavaScript – The malicious logic was implemented in JavaScript inside the extension. (‘vamp/axiom-fetch-intercept.js module’)
  • [T1005 ] Data from Local System – The extensions pulled session and wallet state from localStorage, IndexedDB, and browser-accessible data. (‘searching for stsTokenManager.accessToken’, ‘checks localStorage for account and wallet state’)
  • [T1528 ] Steal Application Access Token – The malware recovered Firebase access tokens and Axiom authentication tokens. (‘retries to recover the victim’s Firebase access token’, ‘collects Axiom authentication tokens’)
  • [T1539 ] Steal Web Session Cookie – Orbit Tracker collected JavaScript-accessible cookies from the browser session. (‘JavaScript-accessible cookies’)
  • [T1132.001 ] Data Encoding: Standard Encoding – Stolen data was Base64-encoded before exfiltration. (‘Base64-encodes the stolen data’)
  • [T1020 ] Automated Exfiltration – Collection and transmission were automatic once the target session was present. (‘The collection is automatic’)
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The exfiltration used browser navigation and web requests to web infrastructure. (‘opens the resulting URL in a new browser window’)
  • [T1041 ] Exfiltration Over C2 Channel – The stolen data was sent to attacker-controlled C2 endpoints. (‘sends it to threat actor-controlled Vercel infrastructure’)
  • [T1102 ] Web Service – The campaign used Vercel and Mozilla Add-ons/Chrome Web Store ecosystems as part of its operational flow. (‘threat actor-controlled Vercel infrastructure’, ‘appeared on Mozilla Add-ons’)

Indicators of Compromise

  • [Chrome Extension IDs ] malicious Chrome listings – ingjjklimdeocggninaaapofondbeopd, nngccnjcllkehfiaidagbffjgbikcoij
  • [Firefox Extension IDs ] malicious Firefox add-ons – [email protected], [email protected]
  • [Chrome Extension IDs ] earlier repackaged extensions – bnolicehjnimmdfkihmojhonickmhegp, kkkoejaiilcofkhggclkbogjpinhjppm
  • [File ] malicious module used for credential/session theft – vamp/axiom-fetch-intercept.js, SHA-256 5b4fbe0658ff76f042c3cc2dfe3d1a3eda963e435a24dfc868cb583bde8c7b91
  • [Domains / URLs ] exfiltration and C2 infrastructure – dcfdc-eight[.]vercel[.]app, snipex-iota[.]vercel[.]app, and susi[.]bonto[.]run; paths include /api/collect?d=, /api/code/, and /collect?d=
  • [Telegram Identifiers ] operator tracking and notification IDs – 7680513699, 8375941889, 6431519296
  • [Email Address ] infrastructure-related identity referenced in the campaign – z1417699@gmail[.]com


Read more: https://socket.dev/blog/chrome-firefox-crypto-data-theft