ShieldGuard browser-extension data-harvesting malware
Malware Activity
Summary
Hide ▲
Show ▼
A malicious ShieldGuard browser extension was dismantled after it was found harvesting sensitive data from crypto users, putting wallet and account information at risk. The extension targeted Binance, Coinbase, MetaMask, and Google services, and could execute remote code through a C2 server. The activity mattered because it could capture balances, transaction histories, and portfolio data while bypassing normal browser protections.
Related Happenings
KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking
Technical Analysis
H score24
First: 14.07.2026 14:55
Last: 14.07.2026 14:55
Sources 1
About this happening:
KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...
KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking
Technical AnalysisAbout this happening: KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...
ModHeader browser extension hidden browsing-history collector
Malware Activity
H score42
First: 13.07.2026 20:17
Last: 13.07.2026 20:17
Sources 1
About this happening:
The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
ModHeader browser extension hidden browsing-history collector
Malware ActivityAbout this happening: The ModHeader browser extension shipped a hidden browsing-history collector in its official store version, exposing about 1.6 million installs to covert domain and...
Silent Swap browser-extension clipboard clipper
Malware Activity
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension clipboard clipper
Malware ActivityAbout this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Search for perplexity ai malicious Chrome extension
Malware Activity
H score29
First: 29.06.2026 21:40
Last: 29.06.2026 21:40
Sources 1
About this happening:
A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Search for perplexity ai malicious Chrome extension
Malware ActivityAbout this happening: A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Dormant remote-controlled JavaScript injection path in Adblock for YouTube Chrome extension
Technical Analysis
H score23
First: 25.06.2026 17:12
Last: 25.06.2026 17:12
Sources 1
About this happening:
A Chrome extension with 10 million+ installs was found to carry a dormant script-injection path, raising the risk of arbitrary JavaScript execution across visited...
Dormant remote-controlled JavaScript injection path in Adblock for YouTube Chrome extension
Technical AnalysisAbout this happening: A Chrome extension with 10 million+ installs was found to carry a dormant script-injection path, raising the risk of arbitrary JavaScript execution across visited...
Timeline
-
18.03.2026 16:15 2 articles · 3mo ago
ShieldGuard identified as a malicious browser extension and disrupted
Technical Analysis UpdateOkta Threat Intelligence identified ShieldGuard as a malicious browser extension that masqueraded as a crypto security tool, harvested wallet addresses, captured full HTML from Binance, Coinbase and MetaMask after login, tracked users across sessions, targeted Google services, and used obfuscation plus a custom JavaScript interpreter to bypass Chrome security restrictions. Researchers also linked the operators to Radex and noted language indicators suggesting Russian-speaking actors, while Okta and industry partners removed the extension from the Chrome Web Store, took down associated domains, disabled backend infrastructure, and blocked user sign-in functionality.
Show sources
- Crypto Scam "ShieldGuard" Dismantled After Malware Discovery — www.infosecurity-magazine.com — 18.03.2026 16:15
- Crypto Scam "ShieldGuard" Dismantled After Malware Discovery — www.infosecurity-magazine.com — 18.03.2026 16:15