Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data
Six Chrome and Firefox extensions linked through shared code, C2 infrastructure, and publishing history have been identified targeting cryptocurrency traders. Four malicious extensions steal authenticated session tokens and wallet data from Axiom Trade and Padre users, while two earlier extensions reveal a pattern of repackaging crypto trading tools. The extensions J7Tracker, VREO, and Orbit Tracker automatically retrieve user information, wallet bundles, Firebase tokens, and application state, then exfiltrate data to threat actor-controlled Vercel deployments. The campaign targets an active trading community with Axiom processing over $15 billion in volume across 650,000 wallets. The malicious code runs inside authenticated sessions, collecting localStorage, IndexedDB data, and API responses containing authentication tokens and wallet keys. Data is Base64-encoded and transmitted via browser navigation to avoid CORS restrictions, enabling account compromise and cryptocurrency theft.
AI Analysis
Technical Summary
Six malicious browser extensions for Chrome and Firefox, linked by shared code and command-and-control infrastructure, target cryptocurrency traders by stealing session tokens and wallet data from Axiom Trade and Padre users. Four of these extensions—J7Tracker, VREO, Orbit Tracker, and one other—automatically collect user information, wallet bundles, Firebase tokens, and application state data from browser storage and API responses during authenticated sessions. The data is Base64-encoded and exfiltrated via browser navigation to bypass CORS restrictions, sending it to attacker-controlled Vercel deployments. This enables attackers to compromise accounts and steal cryptocurrency. The campaign reflects a pattern of repackaging crypto trading tools and targets a high-volume trading community.
Potential Impact
The malicious extensions enable attackers to steal authenticated session tokens and wallet keys, leading to account compromise and potential theft of cryptocurrency assets from affected users. Given the targeted platforms process substantial trading volume and wallet counts, the impact can be significant for individual traders and the broader trading community. The exfiltration method circumvents typical browser security controls, increasing the risk of undetected data theft.
Mitigation Recommendations
No official patches or vendor advisories are provided for these malicious extensions. Users should immediately uninstall the identified extensions (J7Tracker, VREO, Orbit Tracker, and related ones) and avoid installing unverified browser extensions, especially those related to cryptocurrency trading. Employ browser security best practices such as restricting extension permissions and monitoring for suspicious activity. Since these are malicious third-party extensions, remediation involves user action to remove them and vigilance against installing repackaged or untrusted extensions.
Indicators of Compromise
- domain: j7tracker.io
- hash: 5b4fbe0658ff76f042c3cc2dfe3d1a3eda963e435a24dfc868cb583bde8c7b91
- domain: cloudflare.bonto.run
- domain: snapshot.xyz
- domain: susi.bonto.run
Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data
Description
Six Chrome and Firefox extensions linked through shared code, C2 infrastructure, and publishing history have been identified targeting cryptocurrency traders. Four malicious extensions steal authenticated session tokens and wallet data from Axiom Trade and Padre users, while two earlier extensions reveal a pattern of repackaging crypto trading tools. The extensions J7Tracker, VREO, and Orbit Tracker automatically retrieve user information, wallet bundles, Firebase tokens, and application state, then exfiltrate data to threat actor-controlled Vercel deployments. The campaign targets an active trading community with Axiom processing over $15 billion in volume across 650,000 wallets. The malicious code runs inside authenticated sessions, collecting localStorage, IndexedDB data, and API responses containing authentication tokens and wallet keys. Data is Base64-encoded and transmitted via browser navigation to avoid CORS restrictions, enabling account compromise and cryptocurrency theft.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Six malicious browser extensions for Chrome and Firefox, linked by shared code and command-and-control infrastructure, target cryptocurrency traders by stealing session tokens and wallet data from Axiom Trade and Padre users. Four of these extensions—J7Tracker, VREO, Orbit Tracker, and one other—automatically collect user information, wallet bundles, Firebase tokens, and application state data from browser storage and API responses during authenticated sessions. The data is Base64-encoded and exfiltrated via browser navigation to bypass CORS restrictions, sending it to attacker-controlled Vercel deployments. This enables attackers to compromise accounts and steal cryptocurrency. The campaign reflects a pattern of repackaging crypto trading tools and targets a high-volume trading community.
Potential Impact
The malicious extensions enable attackers to steal authenticated session tokens and wallet keys, leading to account compromise and potential theft of cryptocurrency assets from affected users. Given the targeted platforms process substantial trading volume and wallet counts, the impact can be significant for individual traders and the broader trading community. The exfiltration method circumvents typical browser security controls, increasing the risk of undetected data theft.
Defensive Guidance
No official patches or vendor advisories are provided for these malicious extensions. Users should immediately uninstall the identified extensions (J7Tracker, VREO, Orbit Tracker, and related ones) and avoid installing unverified browser extensions, especially those related to cryptocurrency trading. Employ browser security best practices such as restricting extension permissions and monitoring for suspicious activity. Since these are malicious third-party extensions, remediation involves user action to remove them and vigilance against installing repackaged or untrusted extensions.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socket.dev/blog/chrome-firefox-crypto-data-theft"]
- Adversary
- null
- Pulse Id
- 6aa21686ffabe101cf6b37c5
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainj7tracker.io | — | |
domaincloudflare.bonto.run | — | |
domainsnapshot.xyz | — | |
domainsusi.bonto.run | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash5b4fbe0658ff76f042c3cc2dfe3d1a3eda963e435a24dfc868cb583bde8c7b91 | — |
Threat ID: 6aa276e2acd9273b49d8d9f3
Added to database: 09/10/2026, 09:22:42 UTC
Last enriched: 09/10/2026, 09:38:53 UTC
Last updated: 09/10/2026, 16:40:50 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.