Skip to main content
Reconnecting to live updates…

Malicious Chrome and Firefox Extensions Steal Crypto Traders' Session and Wallet Data

0
Medium
Published: 09/10/2026 (09/10/2026, 02:31:34 UTC)
Source: AlienVault OTX General

Description

Six Chrome and Firefox extensions linked through shared code, C2 infrastructure, and publishing history have been identified targeting cryptocurrency traders. Four malicious extensions steal authenticated session tokens and wallet data from Axiom Trade and Padre users, while two earlier extensions reveal a pattern of repackaging crypto trading tools. The extensions J7Tracker, VREO, and Orbit Tracker automatically retrieve user information, wallet bundles, Firebase tokens, and application state, then exfiltrate data to threat actor-controlled Vercel deployments. The campaign targets an active trading community with Axiom processing over $15 billion in volume across 650,000 wallets. The malicious code runs inside authenticated sessions, collecting localStorage, IndexedDB data, and API responses containing authentication tokens and wallet keys. Data is Base64-encoded and transmitted via browser navigation to avoid CORS restrictions, enabling account compromise and cryptocurrency theft.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 09:38:53 UTC

Technical Analysis

Six malicious browser extensions for Chrome and Firefox, linked by shared code and command-and-control infrastructure, target cryptocurrency traders by stealing session tokens and wallet data from Axiom Trade and Padre users. Four of these extensions—J7Tracker, VREO, Orbit Tracker, and one other—automatically collect user information, wallet bundles, Firebase tokens, and application state data from browser storage and API responses during authenticated sessions. The data is Base64-encoded and exfiltrated via browser navigation to bypass CORS restrictions, sending it to attacker-controlled Vercel deployments. This enables attackers to compromise accounts and steal cryptocurrency. The campaign reflects a pattern of repackaging crypto trading tools and targets a high-volume trading community.

Potential Impact

The malicious extensions enable attackers to steal authenticated session tokens and wallet keys, leading to account compromise and potential theft of cryptocurrency assets from affected users. Given the targeted platforms process substantial trading volume and wallet counts, the impact can be significant for individual traders and the broader trading community. The exfiltration method circumvents typical browser security controls, increasing the risk of undetected data theft.

Defensive Guidance

No official patches or vendor advisories are provided for these malicious extensions. Users should immediately uninstall the identified extensions (J7Tracker, VREO, Orbit Tracker, and related ones) and avoid installing unverified browser extensions, especially those related to cryptocurrency trading. Employ browser security best practices such as restricting extension permissions and monitoring for suspicious activity. Since these are malicious third-party extensions, remediation involves user action to remove them and vigilance against installing repackaged or untrusted extensions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socket.dev/blog/chrome-firefox-crypto-data-theft"]
Adversary
null
Pulse Id
6aa21686ffabe101cf6b37c5
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainj7tracker.io
domaincloudflare.bonto.run
domainsnapshot.xyz
domainsusi.bonto.run

Hash

ValueDescriptionCopy
hash5b4fbe0658ff76f042c3cc2dfe3d1a3eda963e435a24dfc868cb583bde8c7b91

Threat ID: 6aa276e2acd9273b49d8d9f3

Added to database: 09/10/2026, 09:22:42 UTC

Last enriched: 09/10/2026, 09:38:53 UTC

Last updated: 09/10/2026, 16:40:50 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses