Malicious Chrome Extension Steals MEXC API Keys via Trading Tool Disguise
These articles are AI-generated summaries. Please check the original sources for full details.
Malicious Chrome Extension Steals MEXC API Keys
A malicious Chrome extension, “MEXC API Automator,” masquerades as a trading tool, successfully stealing API keys from MEXC cryptocurrency exchange users and sending them to attackers via Telegram. Published September 1, 2025, the extension had 29 downloads at the time of reporting.
Why This Matters
Current security models often assume trust within the browser ecosystem, failing to account for compromised extensions. This attack bypasses traditional authentication mechanisms by exploiting an existing, authenticated session, leading to potential for significant financial losses – a single compromised key can grant attackers complete control over a user’s exchange account and associated funds.
Key Insights
- Chrome Web Store vulnerability: Malicious extensions can circumvent vetting processes and reach a wide audience.
- API key abuse: Automated API key generation combined with hidden withdrawal permissions dramatically increases the risk of exploitation.
- Telegram as exfiltration channel: Attackers commonly utilize Telegram bots for rapid credential harvesting and control.
Practical Applications
- Use Case: Attackers leverage compromised browser extensions to target cryptocurrency exchange users directly.
- Pitfall: Assuming browser extension security without robust vetting and runtime monitoring can lead to complete account takeover.
References:
Continue reading
Next article
‘Most Severe AI Vulnerability to Date’ Hits ServiceNow
Related Content
AI-Driven Malware Exploits Open-Source Trust: VS Code Extension and npm Packages
A malicious VS Code extension with ransomware capabilities and 17 npm packages distributing Vidar Infostealer highlight AI's role in modern supply chain attacks, exploiting open-source ecosystems.
Five 2025 Web Security Threats Redefining Cyber Defense
AI-driven attacks and supply chain breaches in 2025 forced a 156% surge in malicious packages and 70% cookie non-compliance, reshaping web security protocols.
Featured Chrome Extensions Silently Harvested Millions of Users’ AI Chat Data
A Google Chrome extension, Urban VPN, with over six million users, was found collecting AI prompts, responses, and browsing data, highlighting a significant data privacy breach.