CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6900

As cited

Copy frozen at (site build).

threat intel

Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

Socket discovered six malicious Chrome and Firefox extensions targeting cryptocurrency traders on Axiom Trade and Padre platforms. The extensions automatically harvest authenticated session tokens, wallet data, and Firebase credentials from users' browsers, then exfiltrate the information to threat actor-controlled infrastructure. Four extensions with identical or linked malicious code were removed from the Chrome Web Store in July 2026, while a fifth extension with similar functionality remains active on Firefox.

Why it matters: Cryptocurrency traders using Axiom Trade or Padre face account compromise and wallet theft if they install these extensions; security teams managing Chrome and Firefox deployments should block the identified extension IDs, search historical inventories for prior installations, and hunt for connections to the command and control domains dcfdc-eight.vercel.app, snipex-iota.vercel.app, and susi.bonto.run.

VendorsGoogleCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

Socket identified six malicious Chrome and Firefox extensions targeting cryptocurrency traders on Axiom Trade and Padre platforms. The extensions, including J7Tracker, VREO, and Orbit Tracker, automatically extract authenticated session tokens, wallet data, Firebase credentials, and browser cookies from logged-in users, then exfiltrate the information to threat actor infrastructure hosted on Vercel and Bonto domains. Four extensions were removed from the Chrome Web Store in July 2026, but Orbit Tracker remained active on Mozilla Add-ons at publication and used separate command and control infrastructure with Telegram notifications to operators.

Why it matters: Cryptocurrency traders using Axiom Trade and Padre face account compromise and direct theft of wallet funds if they installed any of these extensions; defenders managing Chrome and Firefox environments should block the confirmed malicious extension IDs, revoke affected user sessions and tokens, hunt for indicators of compromise on network and endpoint telemetry, and restrict browser extensions in financial and crypto trading profiles to an explicit allowlist.

VendorsGoogleCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary