Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
AI Summary
A coordinated campaign involving malicious Chrome and Firefox extensions has been targeting cryptocurrency traders using Axiom Trade and Padre (now Terminal) platforms. The extensions, including J7Tracker, VREO, and Orbit Tracker, steal authenticated session tokens, wallet data, and browser state by injecting malicious JavaScript modules into active trading sessions. Data is exfiltrated via browser navigation to attacker-controlled domains hosted on Vercel and bonto.run infrastructure, bypassing CORS restrictions. The threat actor uses repackaged extensions with cloned functionality and maintains persistence through rotating C2 infrastructure and new publisher accounts, posing a direct risk of account compromise and cryptocurrency theft.
AI-extracted · verify before operational use
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 5b4fbe0658ff76f042c3cc2dfe3d1a3eda963e435a24dfc868cb583bde8c7b91 | Details → |
| Domain | dcfdc-eight[.]vercel[.]app | Details → |
| Domain | snipex-iota[.]vercel[.]app | Details → |
| Domain | susi[.]bonto[.]run | Details → |
| Domain | cloudflare[.]bonto[.]run | Details → |
| Filename | vamp/axiom-fetch-intercept.js | Details → |
| GitHub User | j7tracker.io | Details → |
| GitHub User | snapshot.xyz | Details → |
| Registry User | [email protected] | Details → |
| IP | 6431519296 | Details → |