socket-dev · Crawled Sep 10, 2026

Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

10 IoCs
Read original article ↗

AI Summary

A coordinated campaign involving malicious Chrome and Firefox extensions has been targeting cryptocurrency traders using Axiom Trade and Padre (now Terminal) platforms. The extensions, including J7Tracker, VREO, and Orbit Tracker, steal authenticated session tokens, wallet data, and browser state by injecting malicious JavaScript modules into active trading sessions. Data is exfiltrated via browser navigation to attacker-controlled domains hosted on Vercel and bonto.run infrastructure, bypassing CORS restrictions. The threat actor uses repackaged extensions with cloned functionality and maintains persistence through rotating C2 infrastructure and new publisher accounts, posing a direct risk of account compromise and cryptocurrency theft.

AI-extracted · verify before operational use

Indicators of Compromise 10 extracted

Type Value Detail
SHA-256 5b4fbe0658ff76f042c3cc2dfe3d1a3eda963e435a24dfc868cb583bde8c7b91 Details →
Domain dcfdc-eight[.]vercel[.]app Details →
Domain snipex-iota[.]vercel[.]app Details →
Domain susi[.]bonto[.]run Details →
Domain cloudflare[.]bonto[.]run Details →
Filename vamp/axiom-fetch-intercept.js Details →
GitHub User j7tracker.io Details →
GitHub User snapshot.xyz Details →
Registry User [email protected] Details →
IP 6431519296 Details →