Malicious imToken Chrome Extension Caught Stealing Mnemonics and Private Keys
## Cybersecurity: Malicious Chrome Extension Targeting Cryptocurrency Wallets
Cybersecurity: Malicious Chrome Extension Targeting Cryptocurrency Wallets
Socket's Threat Research Team has identified a malicious Google Chrome extension named "lmToken Chromophore," which is designed to steal cryptocurrency wallet credentials.
The extension falsely presents itself as a harmless hex color visualizer while impersonating the non-custodial wallet brand imToken. imToken, a platform with over 20 million global users since its 2016 launch, is a significant target for phishing attacks. The official imToken team has clarified that their platform is a mobile application and no Chrome extension has been released by them.
The malicious extension's aim is to deceive users into providing their 12 or 24-word seed phrases or plaintext private keys, resulting in unauthorized access to wallets.
Upon installation, the extension disregards its claimed color-picking function and operates as a redirector. It fetches a target website from a hardcoded remote endpoint hosted on JSONKeeper, redirecting users to the attacker's site. This setup allows dynamic phishing destination changes without updating the extension code in the Chrome Web Store.
The extension falsely presents itself as a harmless hex color visualizer while impersonating the non-custodial wallet brand imToken.
The initial redirect leads to a phishing domain named chroomewedbstorre-detail-extension[.]com . To bypass security scanners, the attackers use mixed-script Unicode homoglyphs, replacing standard Latin letters with similar-looking Cyrillic and Greek characters.
On the phishing page, users are presented with a fraudulent wallet import interface powered by external JavaScript files. It prompts users to enter their mnemonic seed phrase or private key, and after gathering the data, it deceives users with a fake "upgrading" loading screen before redirecting them to the official token.im website.
Security teams should apply rigorous scrutiny to browser extensions, similar to traditional third-party software. Organizations are advised to limit extension installations in sensitive browser profiles. Users should authenticate wallet software through official vendor channels. If a seed phrase, private key, or wallet password has been entered into a suspected phishing site, users must consider the wallet compromised and transfer funds to secure keys immediately.
Security tools should monitor extensions that fetch remote content and open external destinations. The following Indicators of Compromise (IOCs) should be integrated into detection pipelines:
Malicious Extension ID: bbhaganppipihlhjgaaeeeefbaoihcgi Publisher Email Address: liomassi19855@gmail[.]com Primary Phishing Landing Page: chroomewedbstorre-detail-extension[.]com Remote Configuration Payload: jsonkeeper[.]com/b/KUWNE Malicious Script Infrastructure: compute-fonts-appconnect.pages[.]dev
Based on reporting by Cyber Security News.
