Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious imToken Chrome Extension Caught Stealing Mnemonics and Private Keys

## Cybersecurity: Malicious Chrome Extension Targeting Cryptocurrency Wallets

Cybersecurity: Malicious Chrome Extension Targeting Cryptocurrency Wallets

Socket's Threat Research Team has identified a malicious Google Chrome extension named "lmToken Chromophore," which is designed to steal cryptocurrency wallet credentials.

The extension falsely presents itself as a harmless hex color visualizer while impersonating the non-custodial wallet brand imToken. imToken, a platform with over 20 million global users since its 2016 launch, is a significant target for phishing attacks. The official imToken team has clarified that their platform is a mobile application and no Chrome extension has been released by them.

The malicious extension's aim is to deceive users into providing their 12 or 24-word seed phrases or plaintext private keys, resulting in unauthorized access to wallets.

Upon installation, the extension disregards its claimed color-picking function and operates as a redirector. It fetches a target website from a hardcoded remote endpoint hosted on JSONKeeper, redirecting users to the attacker's site. This setup allows dynamic phishing destination changes without updating the extension code in the Chrome Web Store.

The extension falsely presents itself as a harmless hex color visualizer while impersonating the non-custodial wallet brand imToken.
Julia Kramer · Thehackingpost

The initial redirect leads to a phishing domain named chroomewedbstorre-detail-extension[.]com . To bypass security scanners, the attackers use mixed-script Unicode homoglyphs, replacing standard Latin letters with similar-looking Cyrillic and Greek characters.

On the phishing page, users are presented with a fraudulent wallet import interface powered by external JavaScript files. It prompts users to enter their mnemonic seed phrase or private key, and after gathering the data, it deceives users with a fake "upgrading" loading screen before redirecting them to the official token.im website.

Security teams should apply rigorous scrutiny to browser extensions, similar to traditional third-party software. Organizations are advised to limit extension installations in sensitive browser profiles. Users should authenticate wallet software through official vendor channels. If a seed phrase, private key, or wallet password has been entered into a suspected phishing site, users must consider the wallet compromised and transfer funds to secure keys immediately.

Advertisement

Security tools should monitor extensions that fetch remote content and open external destinations. The following Indicators of Compromise (IOCs) should be integrated into detection pipelines:

Malicious Extension ID: bbhaganppipihlhjgaaeeeefbaoihcgi Publisher Email Address: liomassi19855@gmail[.]com Primary Phishing Landing Page: chroomewedbstorre-detail-extension[.]com Remote Configuration Payload: jsonkeeper[.]com/b/KUWNE Malicious Script Infrastructure: compute-fonts-appconnect.pages[.]dev

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories