Application security, API security

MEXC API keys targeted by illicit Chrome extension

Centralized cryptocurrency exchange MEXC is being targeted by an illicit Google Chrome extension that aims to steal its API keys, according to The Hacker News.

Multiple MEXC API keys created by the extension with appropriate permissions have enabled account takeovers for trade execution, automated withdrawal, and wallet draining activities without needing users' credentials or evading authentication protections, according to an analysis from Socket. Navigating to the crypto exchange's API management page triggers the extension to inject script.js into the authenticate session, with both Access Key and Secret Key then exfiltrated to a hard-coded Telegram bot. Moreover, hijacked MEXC accounts could be continuously accessed by threat actors unless keys are revoked.

"The same playbook can be readily adapted to other exchanges, DeFi dashboards, broker portals, and any web console that issues tokens in session, and future variants are likely to introduce heavier obfuscation, request broader browser permissions, and bundle support for multiple platforms into a single extension," researchers added.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds