Crypto Extensions Drain Wallets While AI Agents Automate Global Attacks
Researchers have uncovered a coordinated campaign of malicious browser extensions targeting cryptocurrency traders on both Chrome and Firefox. Four extensions — J7Tracker, VREO, and Orbit Tracker — were designed to steal session tokens, wallet data, and Firebase access tokens from users of Axiom Trade and Padre. According to Socket, the modules used in the attack are byte-identical across the Chrome variants and exfiltrate authenticated user information to threat actor-controlled Vercel deployments. The same Chrome publisher has been linked to two earlier impersonator extensions, GhostApe and GhostApe Color, which mimicked the legitimate MockApe trading tool — a textbook example of how reputation and trust can be weaponized inside extension marketplaces. Users who suspect exposure should immediately run an email breach checker to see if their credentials have surfaced, and test whether their browser is leaking identifying data via our browser fingerprint test.
In a separate operation, a Chinese-speaking threat actor has been observed leveraging Anthropic's Claude Code, Alibaba's Qwen, and DeepSeek to automate end-to-end cyber intrusions against government and financial targets across Asia and the U.S. The campaign hit Taiwan's Kuomintang Party History Archives, Indonesia's Ministry of Foreign Affairs, government and education systems in mainland China, and industrial hosts in Da Nang, Vietnam, as well as entities in Afghanistan and Thailand. Hunt.io attributes the orchestration to SecFlow, an AI framework that splits reconnaissance, exploitation, collection, and reporting among specialist AI agents. The threat actor chained together a roster of legacy and recent vulnerabilities — Shellshock, Spring4Shell, Ghostcat, Apache Shiro deserialization, Log4Shell, Grafana and Nexus path traversals, and a Nacos authentication bypass — before deploying web shells generated by a custom capability dubbed GLUTTON.
Together, these stories highlight a recurring theme: attackers no longer need novel exploits when trusted tools and AI-augmented workflows can carry the load. Web shells, session hijackers, and AI-driven reconnaissance all depend on weak edges and exposed services to gain initial entry. Defenders should harden exposed infrastructure by scanning for open services with our port scanner and validating TLS configurations through the SSL/TLS checker, while individuals should audit installed browser extensions and rotate any crypto-related credentials immediately.