Malicious Browser Add‑on Targets imToken Users’ Private Keys
## Cybersecurity: Malicious Chrome Extension Targeting Cryptocurrency Users
Cybersecurity: Malicious Chrome Extension Targeting Cryptocurrency Users
Socket's Threat Research Team has identified a deceptive Google Chrome extension designed to steal private keys and seed phrases from cryptocurrency users.
The extension, named "lmΤoken Chromophore" (extension ID bbhaganppipihlhjgaaeeeefbaoihcgi), masquerades as a hex color visualizer for developers but aims to impersonate the non-custodial wallet brand, imToken, to collect sensitive wallet recovery information.
The extension triggers its phishing attack upon installation and any subsequent user interaction, capitalizing on the imToken brand, which is solely a mobile application and does not have an official Chrome extension.
Technical Analysis of the Phishing Attack
The malicious extension employs advanced evasion techniques to avoid detection by automated tools and manual reviews. It functions as a lightweight browser redirector with no direct theft logic. Upon installation, a background script retrieves a phishing URL from an external configuration endpoint, redirecting users to a counterfeit site.
Socket's Threat Research Team has identified a deceptive Google Chrome extension designed to steal private keys and seed phrases from cryptocurrency users.
The phishing site uses mixed-script Unicode homoglyphs for evasion, displaying titles like "іmΤоken" with characters from different scripts. Users are prompted to enter seed phrases or private keys, granting attackers full control over the associated cryptocurrency funds. The workflow ends with a redirection to the legitimate token.im site as a decoy.
Security experts should be wary of browser extensions executing remote configurations or redirecting to external sites. Key indicators include:
Extension ID: bbhaganppipihlhjgaaeeeefbaoihcgi Extension Name: lmΤoken Chromophore Phishing Domain: chroomewedbstorre-detail-extension.com Configuration Endpoint: jsonkeeper.com/b/KUWNE
Organizations and users must treat browser extensions as high-risk and restrict installations in sensitive environments. Always verify cryptocurrency-related software through official channels. If a seed phrase or private key is compromised, move assets to a new wallet with fresh keys immediately.
Based on reporting by GBHackers.
