Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

· Original article ↗

Summary

Socket traced malicious browser extensions targeting Axiom Trade and Padre users. The extensions harvest authenticated session and wallet-related data and send it to attacker-controlled infrastructure.

Key points

  • J7Tracker and VREO extensions for Chrome and Firefox share a byte-identical data-collection module; Firefox’s Orbit Tracker uses separate code and command-and-control infrastructure.
  • The extensions target authenticated Axiom Trade and Padre sessions, collecting user information, wallet-related application state, tokens, and, in Orbit Tracker’s case, cookies.
  • Data is sent to attacker-controlled Vercel or Bonto infrastructure, with some extensions using browser navigation to exfiltrate data without ordinary extension host permissions.
  • Socket linked the extensions through shared code, infrastructure, publishing history, cloned trading tools, and marketplace artifacts, tracing earlier associated extensions GhostApe and GhostApe Color to the same publisher portfolio.
  • Chrome listings were removed in July 2026; Orbit Tracker remained available on Firefox at publication, and Socket reported it to Mozilla.
  • Socket recommends blocking the identified extension IDs, revoking affected sessions and tokens, reviewing wallet activity, and checking telemetry and browser inventories for indicators of compromise.

Article Details

Attack Vectors
  • Malicious Chrome and Firefox extensions distributed through browser marketplaces execute within authenticated Axiom Trade and Padre sessions.
  • J7Tracker and VREO collect authenticated user information, wallet-related bundle data, Firebase access tokens, and application state. On Padre, their collector reads localStorage and falls back to Firebase Auth data in IndexedDB.
  • The J7Tracker and VREO collector Base64-encodes stolen data and exfiltrates it through browser navigation to threat actor-controlled Vercel deployments, rather than using conventional cross-origin requests.
  • Orbit Tracker collects Axiom authentication tokens, JavaScript-accessible cookies, user information, sBundles, and bundleKey. It sends the data to its collection endpoint and separately notifies the operator through Telegram.
  • GhostApe appears to be a repackaged, brandjacking derivative of MockApe; the article does not establish that GhostApe or GhostApe Color contains the collection module.
Defensive Notes
  • Block the confirmed malicious extension IDs and search historical browser inventories for prior installations; review the GhostApe extension IDs separately for exposure.
  • Revoke affected Axiom Trade and Padre sessions and authentication tokens, rotate relevant credentials, and review wallet and trading activity for unauthorized transactions.
  • Hunt DNS, proxy, browser, and EDR telemetry for the listed collection hosts and paths. Preserve full URLs where available because exfiltrated data is encoded into requests.
  • Review extension updates for changes to content scripts, permissions, network destinations, publisher identity, and access to localStorage, IndexedDB, cookies, and authenticated application APIs.
  • Allowlist extensions in browser profiles used for high-value accounts and isolate sensitive sessions from unnecessary third-party extensions.

Indicators of compromise

TypeIndicatorContext
EMAILz1417699@gmail[.]comDeveloper email listed for the malicious VREO Chrome Web Store extension.
HOSTNAMEcloudflare[.]bonto[.]runHost listed under Orbit Tracker threat actor infrastructure.
HOSTNAMEdcfdc-eight[.]vercel[.]appThreat actor-controlled J7Tracker and VREO exfiltration host.
HOSTNAMEsnipex-iota[.]vercel[.]appThreat actor infrastructure listed for J7Tracker and VREO.
HOSTNAMEsusi[.]bonto[.]runOrbit Tracker exfiltration host for collected Axiom session and wallet-related data.
SHA2565b4fbe0658ff76f042c3cc2dfe3d1a3eda963e435a24dfc868cb583bde8c7b91SHA-256 of the malicious vamp/axiom-fetch-intercept.js module.
URLhxxps[:]//dcfdc-eight[.]vercel[.]app/api/collect?d=J7Tracker and VREO collection URL prefix used to transmit encoded stolen data.
URLhxxps[:]//snipex-iota[.]vercel[.]app/api/code/Threat actor infrastructure URL listed for J7Tracker and VREO.
URLhxxps[:]//susi[.]bonto[.]run/collect?d=Orbit Tracker collection URL prefix for stolen data.

MITRE ATT&CK

T1005 · Data from Local SystemThe collectors read locally stored trading-application data from localStorage and, for Padre token recovery, IndexedDB.T1020 · Automated ExfiltrationThe extensions automatically collect and transmit data when targeted application state becomes available.T1036 · MasqueradingGhostApe appears to be a repackaged, brandjacking derivative of the established MockApe trading extension.T1041 · Exfiltration Over C2 ChannelThe extensions exfiltrate session and wallet-related data to their threat actor-controlled collection infrastructure.T1059.007 · JavaScriptJavaScript in the extensions reads trading-application state and sends collected data externally.T1071.001 · Web ProtocolsThe collectors transmit stolen data through web requests or browser navigation to collection endpoints.T1102 · Web ServiceJ7Tracker and VREO use threat actor-controlled Vercel deployments as collection infrastructure.T1132.001 · Standard EncodingThe J7Tracker and VREO collector Base64-encodes stolen data before placing it in a collection URL.T1176.001 · Browser ExtensionsMalicious Chrome and Firefox extensions run collectors inside authenticated trading-platform pages.T1204 · User ExecutionThe operation relies on users installing extensions distributed through trusted browser marketplaces.T1528 · Steal Application Access TokenThe extensions retrieve Firebase access tokens or Axiom authentication tokens from authenticated browser sessions.T1539 · Steal Web Session CookieOrbit Tracker collects JavaScript-accessible cookies from the targeted session.

People

Malware

Vendors

Products

Axiom TradeFour malicious Chrome and Firefox extensions steal authenticated Axiom Trade and Padre session and wallet-related data, while two earlier extensions linked to the same publisher operation reveal a longer-running patternChrome Web StoreMockApe API references, internal identifiers, version lineage, and even the legitimate MockApe Chrome Web Store ID. GhostApe and GhostApe Color also share an exact binary image. Archived marketplace data placesGhostApeOur investigation also traced the Chrome publisher portfolio back to two earlier extensions, GhostApe and GhostApe Color. GhostApe appears to be a repackaged, brandjacking derivative of the established MockApe tradingGhostApe Colorinvestigation also traced the Chrome publisher portfolio back to two earlier extensions, GhostApe and GhostApe Color. GhostApe appears to be a repackaged, brandjacking derivative of the established MockApe tradingGoogle ChromeFour malicious Chrome and Firefox extensions steal authenticated Axiom Trade and Padre session and wallet-related data, while two earlier extensions linked to the same publisher operation reveal a longer-running patternMockApeand GhostApe Color. GhostApe appears to be a repackaged, brandjacking derivative of the established MockApe trading extension, retaining MockApe API references, internal identifiers, version lineage, and even theMozilla Add-onsSeveral weeks later, Orbit Tracker appeared on Mozilla Add-ons under a newly created Mozilla Add-ons publisher profile with only one extension.Mozilla FirefoxFour malicious Chrome and Firefox extensions steal authenticated Axiom Trade and Padre session and wallet-related data, while two earlier extensions linked to the same publisher operation reveal a longer-running patternPadreFour malicious Chrome and Firefox extensions steal authenticated Axiom Trade and Padre session and wallet-related data, while two earlier extensions linked to the same publisher operation reveal a longer-running patternTerminalcloned crypto trading tools, marketplace artifacts, and specific targeting of Axiom Trade and Padre (now Terminal) users.

Industries

Related Articles