As cited
Copy frozen at (site build).
threat intel
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Socket discovered six malicious Chrome and Firefox extensions targeting cryptocurrency traders on Axiom Trade and Padre platforms. The extensions automatically harvest authenticated session tokens, wallet data, and Firebase credentials from users' browsers, then exfiltrate the information to threat actor-controlled infrastructure. Four extensions with identical or linked malicious code were removed from the Chrome Web Store in July 2026, while a fifth extension with similar functionality remains active on Firefox.
Why it matters: Cryptocurrency traders using Axiom Trade or Padre face account compromise and wallet theft if they install these extensions; security teams managing Chrome and Firefox deployments should block the identified extension IDs, search historical inventories for prior installations, and hunt for connections to the command and control domains dcfdc-eight.vercel.app, snipex-iota.vercel.app, and susi.bonto.run.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Socket identified six malicious Chrome and Firefox extensions targeting cryptocurrency traders on Axiom Trade and Padre platforms. The extensions, including J7Tracker, VREO, and Orbit Tracker, automatically extract authenticated session tokens, wallet data, Firebase credentials, and browser cookies from logged-in users, then exfiltrate the information to threat actor infrastructure hosted on Vercel and Bonto domains. Four extensions were removed from the Chrome Web Store in July 2026, but Orbit Tracker remained active on Mozilla Add-ons at publication and used separate command and control infrastructure with Telegram notifications to operators.
Why it matters: Cryptocurrency traders using Axiom Trade and Padre face account compromise and direct theft of wallet funds if they installed any of these extensions; defenders managing Chrome and Firefox environments should block the confirmed malicious extension IDs, revoke affected user sessions and tokens, hunt for indicators of compromise on network and endpoint telemetry, and restrict browser extensions in financial and crypto trading profiles to an explicit allowlist.
- Source published
- First seen by Cybersecurity Tracker