Centralized cryptocurrency exchange MEXC is being targeted by an illicit Google Chrome extension that aims to steal its API keys, according to The Hacker News.Multiple MEXC API keys created by the extension with appropriate permissions have enabled account takeovers for trade execution, automated withdrawal, and wallet draining activities without needing users' credentials or evading authentication protections, according to an analysis from Socket. Navigating to the crypto exchange's API management page triggers the extension to inject script.js into the authenticate session, with both Access Key and Secret Key then exfiltrated to a hard-coded Telegram bot. Moreover, hijacked MEXC accounts could be continuously accessed by threat actors unless keys are revoked."The same playbook can be readily adapted to other exchanges, DeFi dashboards, broker portals, and any web console that issues tokens in session, and future variants are likely to introduce heavier obfuscation, request broader browser permissions, and bundle support for multiple platforms into a single extension," researchers added.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds





