Bitcoin Forum
May 04, 2024, 05:43:09 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Web3 Extension Malware  (Read 185 times)
zasad@ (OP)
Legendary
*
Offline Offline

Activity: 1750
Merit: 4273



View Profile WWW
August 21, 2022, 09:47:59 AM
Merited by hugeblack (4), DdmrDdmr (3), TryNinja (2)
 #1

https://twitter.com/wallet_guard/status/1561046182645751810?
"There is a new scam going around that leverages a chrome extension to intercept and modify your exchange deposit address & withdrawal requests. This means that even if you double check your addresses, you can still become a victim 1/🧵"

https://medium.com/@walletguardofficial/web3-extension-malware-google-sheets-ac6d9fb6658d
Web3 Extension Malware — ‘Google Sheets’




.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
1714844589
Hero Member
*
Offline Offline

Posts: 1714844589

View Profile Personal Message (Offline)

Ignore
1714844589
Reply with quote  #2

1714844589
Report to moderator
1714844589
Hero Member
*
Offline Offline

Posts: 1714844589

View Profile Personal Message (Offline)

Ignore
1714844589
Reply with quote  #2

1714844589
Report to moderator
1714844589
Hero Member
*
Offline Offline

Posts: 1714844589

View Profile Personal Message (Offline)

Ignore
1714844589
Reply with quote  #2

1714844589
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714844589
Hero Member
*
Offline Offline

Posts: 1714844589

View Profile Personal Message (Offline)

Ignore
1714844589
Reply with quote  #2

1714844589
Report to moderator
1714844589
Hero Member
*
Offline Offline

Posts: 1714844589

View Profile Personal Message (Offline)

Ignore
1714844589
Reply with quote  #2

1714844589
Report to moderator
1714844589
Hero Member
*
Offline Offline

Posts: 1714844589

View Profile Personal Message (Offline)

Ignore
1714844589
Reply with quote  #2

1714844589
Report to moderator
Jawhead999
Legendary
*
Offline Offline

Activity: 1652
Merit: 1156



View Profile
August 21, 2022, 10:33:01 AM
 #2

This discussion has been created before Fake Google Sheets Extension - Scammed | New Update!

This is the reason why anyone should pay attention when installing an extension and if it's not that important, you shouldn't need to install.

Anyway someone on the tweet have pointed out how to check if the extension is genuine and not the fake one.

If you want to check that you're not affected - check the source of your extensions. On Chrome:

Manage extensions -> click "details" for the extension you'd like to check -> ensure that the "Source" is "Chrome Web Store"

.freebitcoin.       ▄▄▄█▀▀██▄▄▄
   ▄▄██████▄▄█  █▀▀█▄▄
  ███  █▀▀███████▄▄██▀
   ▀▀▀██▄▄█  ████▀▀  ▄██
▄███▄▄  ▀▀▀▀▀▀▀  ▄▄██████
██▀▀█████▄     ▄██▀█ ▀▀██
██▄▄███▀▀██   ███▀ ▄▄  ▀█
███████▄▄███ ███▄▄ ▀▀▄  █
██▀▀████████ █████  █▀▄██
 █▄▄████████ █████   ███
  ▀████  ███ ████▄▄███▀
     ▀▀████   ████▀▀
BITCOIN
DICE
EVENT
BETTING
WIN A LAMBO !

.
            ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
▄▄▄▄▄██████████████████████████████████▄▄▄▄
▀██████████████████████████████████████████████▄▄▄
▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
  ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
       ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.PLAY NOW.
OcTradism
Hero Member
*****
Offline Offline

Activity: 1736
Merit: 801



View Profile WWW
August 21, 2022, 11:44:20 AM
 #3

I always try to limit the applications I install on my PC, laptop and mobile devices. The more softwares, applications, extensions I install on my devices, the more risk I will have. Prevention is better than cure and installation reduction is prevention.

If I install anything, I will get it from official sources. Officially visit websites & download apps, not fake ones.

I don't install anything because I am curious of something new. Sometimes you will receive emails from senders that look to be legit but they are not.

Punycode and how to protect yourself from Homograph Phishing attacks?

.
.Duelbits.
█▀▀▀▀▀











█▄▄▄▄▄
TRY OUR
  NEW  UNIQUE
GAMES!
.
..DICE...
███████████████████████████████
███▀▀                     ▀▀███
███    ▄▄▄▄         ▄▄▄▄    ███
███   ██████       ██████   ███
███   ▀████▀       ▀████▀   ███
███                         ███
███                         ███
███                         ███
███   ▄████▄       ▄████▄   ███
███   ██████       ██████   ███
███    ▀▀▀▀         ▀▀▀▀    ███
███▄▄                     ▄▄███
███████████████████████████████
.
.MINES.
███████████████████████████████
████████████████████████▄▀▄████
██████████████▀▄▄▄▀█████▄▀▄████
████████████▀ █████▄▀████ █████
██████████      █████▄▀▀▄██████
███████▀          ▀████████████
█████▀              ▀██████████
█████                ██████████
████▌                ▐█████████
█████                ██████████
██████▄            ▄███████████
████████▄▄      ▄▄█████████████
███████████████████████████████
.
.PLINKO.
███████████████████████████████
█████████▀▀▀       ▀▀▀█████████
██████▀  ▄▄███ ███      ▀██████
█████  ▄▀▀                █████
████  ▀                    ████
███                         ███
███                         ███
███                         ███
████                       ████
█████                     █████
██████▄                 ▄██████
█████████▄▄▄       ▄▄▄█████████
███████████████████████████████
10,000x
MULTIPLIER
NEARLY UP TO
.50%. REWARDS
▀▀▀▀▀█











▄▄▄▄▄█
Charles-Tim
Legendary
*
Offline Offline

Activity: 1540
Merit: 4842



View Profile
August 21, 2022, 12:04:20 PM
 #4

I always try to limit the applications I install on my PC, laptop and mobile devices. The more softwares, applications, extensions I install on my devices, the more risk I will have. Prevention is better than cure and installation reduction is prevention.
That is how it suppose to be, to avoid malware, by visiting just official websites. But we should also remember there are other things to do to avoid malware, especially by avoiding ads and torrent files.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
OcTradism
Hero Member
*****
Offline Offline

Activity: 1736
Merit: 801



View Profile WWW
August 21, 2022, 01:03:07 PM
 #5

That is how it suppose to be, to avoid malware, by visiting just official websites. But we should also remember there are other things to do to avoid malware, especially by avoiding ads and torrent files.
Unfortunately, there are so many traps from scammers and newbies are easily and naively to be caught by scammers. Even not newbies still can be caught if they are careless at some points.

It is like in cryptocurrency, I learned an important thing. Don't trust, verify and double check. Even you receive email that looks to be legit, you must go to an exchange and double check for latest announcements, news from their official site. If there is nothing relates to the email you receive, be careful it can be punny code, homograph attacks.

DMs from strangers, simply ignore, block and report them as scammers.

.
.Duelbits.
█▀▀▀▀▀











█▄▄▄▄▄
TRY OUR
  NEW  UNIQUE
GAMES!
.
..DICE...
███████████████████████████████
███▀▀                     ▀▀███
███    ▄▄▄▄         ▄▄▄▄    ███
███   ██████       ██████   ███
███   ▀████▀       ▀████▀   ███
███                         ███
███                         ███
███                         ███
███   ▄████▄       ▄████▄   ███
███   ██████       ██████   ███
███    ▀▀▀▀         ▀▀▀▀    ███
███▄▄                     ▄▄███
███████████████████████████████
.
.MINES.
███████████████████████████████
████████████████████████▄▀▄████
██████████████▀▄▄▄▀█████▄▀▄████
████████████▀ █████▄▀████ █████
██████████      █████▄▀▀▄██████
███████▀          ▀████████████
█████▀              ▀██████████
█████                ██████████
████▌                ▐█████████
█████                ██████████
██████▄            ▄███████████
████████▄▄      ▄▄█████████████
███████████████████████████████
.
.PLINKO.
███████████████████████████████
█████████▀▀▀       ▀▀▀█████████
██████▀  ▄▄███ ███      ▀██████
█████  ▄▀▀                █████
████  ▀                    ████
███                         ███
███                         ███
███                         ███
████                       ████
█████                     █████
██████▄                 ▄██████
█████████▄▄▄       ▄▄▄█████████
███████████████████████████████
10,000x
MULTIPLIER
NEARLY UP TO
.50%. REWARDS
▀▀▀▀▀█











▄▄▄▄▄█
Saint-loup
Legendary
*
Offline Offline

Activity: 2604
Merit: 2353



View Profile
August 21, 2022, 01:18:17 PM
 #6

https://twitter.com/wallet_guard/status/1561046182645751810?
"There is a new scam going around that leverages a chrome extension to intercept and modify your exchange deposit address & withdrawal requests. This means that even if you double check your addresses, you can still become a victim 1/🧵"

https://medium.com/@walletguardofficial/web3-extension-malware-google-sheets-ac6d9fb6658d
Web3 Extension Malware — ‘Google Sheets’
Thank you to have posted that in the beginners section. It reminds us to always being very careful with extensions, plugins, add-ons, patchs and anything modifying the initial code of a software. I try to avoid them the more I can because I don't even totally trust the official branded stores of softwares I use to deal with cryptos.

██
██
██
██
██
██
██
██
██
██
██
██
██
... LIVECASINO.io    Play Live Games with up to 20% cashback!...██
██
██
██
██
██
██
██
██
██
██
██
██
cheezcarls
Hero Member
*****
Offline Offline

Activity: 2254
Merit: 658


Revolutionized copy gaming platform


View Profile
August 21, 2022, 01:31:37 PM
 #7

We just have to be very extra careful in installing these extensions, plugins, etc. If we do not do our due diligence, we will likely become easy victims of the scammer.

A few months ago, I was stupid enough not to doing my due diligence believing that everything was real until a few hours later I see my wallets getting drained for a grand total of $12k+. It might not be big to you guys, but it is for me as a 3rd world country guy.

And also when it comes to emails, I usually do not really believe in them as I definitely go to the official website and social media channels to make sure if its really from them or not.

Pla
                             ▄██████████▌
████             ▐███████████▌
  ████         ▐████    ███
   ▐████     ▐████     ███       ███      ▂▃▅
     ████    ████        ███      ███████
        ███    ████        ███      ███████
         ▐██    ████        ███      ███          
                 █████         ███      ███
              █████▌         ███      ███
           █████▌            ███      ███
     ██████▌
███████
ade.win
██            ██
██            ██
██            ██
██         ██
  ▌         ██
  ▌   ██    ██
        ██    ██
        ██      ▌
        ██      ▌
        ██
        ██
.R E V O L U T I O N A R Y   C O P Y   G A M I N G   P L A T F O R M  .
██            ██
██            ██
██            ██
██         ██ 
  ▌         ██
  ▌   ██    ██
        ██    ██
        ██      ▌
        ██      ▌
        ██
        ██
█▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀█
█ ████▀▀▀▀▀███████▀▀▀████ █
█ █████▄  █ ████▀  ▄█████ █
█ ██████▄  █ █▀  ▄███████ █
█ ███████▄  █  ▄█████████ █
█ ████████▄  █ ██████████ █
█ ██████▀  ▄█▄ █ ████████ █
█ ████▀  ▄███▄  █ ███████ █
█ ██▀   ██████▄  █ ██████ █
█ ██▄▄▄████████▄▄▄▄▄█████ █
█▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄█
Play Smart Win Big!
StormHawk
Member
**
Offline Offline

Activity: 219
Merit: 12


View Profile
August 21, 2022, 03:54:59 PM
 #8

I've always hated chrome extensions, they aren't safe no matter what you preach to me, this is why I don't use metamask on PC until they build a mobile version year back, in fact anything related to crypto apart from crypto mining must stay off your PC especially if you browse the internet with the PC.

██████████████ ███████ █│     S y n t r u m     │     JOIN NOW     │█ ███████ ██████████████
►   Blockchain Infrastructure for DeFi, Gaming and NFT   ◄
██████████████       |       Twitter       |     Telegram     |      Medium      |       ██████████████
Phu Juck
Member
**
Offline Offline

Activity: 93
Merit: 27


View Profile
August 21, 2022, 04:28:17 PM
 #9

Wow, your warning is very important.
Hackers are always going to abuse bad code, take advantage from it and steal ppl's coins.

Polkadot really needs to solve such issues or it will result in ppl losing Polkadot coins and tokens build on Polkadot supported by web3.

Infections can easily happen and we should be aware to store our coins mostly offline, not in hot wallets and foreign party manufacturers.
Internet and digital space are still very insecure and experienced hackers will exploit flawed code.
It's a very big risk.
JollyGood
Legendary
*
Offline Offline

Activity: 2534
Merit: 1713


Top Crypto Casino


View Profile
August 21, 2022, 10:49:35 PM
 #10

As far as I know, when adding a chrome extension in most if not all cases you are effectively giving permission several things you would normally never even consider doing such as (depending on what extension you install and for what purpose) allowing access to your data for all the browsing you have done and to read and modify your privacy settings as well as control your browser proxy settings.

When adding any extension you really have to be very careful because you have no idea if it is a front for a fake service created in order to access/steal your data.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
robelneo
Legendary
*
Offline Offline

Activity: 3234
Merit: 1202


Bons.io Telegram Casino


View Profile WWW
August 22, 2022, 12:01:00 PM
 #11

I always try to limit the applications I install on my PC, laptop and mobile devices. The more softwares, applications, extensions I install on my devices, the more risk I will have. Prevention is better than cure and installation reduction is prevention.
That is how it suppose to be, to avoid malware, by visiting just official websites. But we should also remember there are other things to do to avoid malware, especially by avoiding ads and torrent files.

The most harmful ones are the ones coming from porn sites even if you have a premium anti-virus and malware fighter there's a possibility that few of them can get in, I have a friend who thinks that these anti-virus and malware remover can intercept all these pop-ups and force to download items, but there are a few pop-ups and call to action ads that get in bypassing your anti-virus, no problem watching porn occasionally but be sure to only browse safe porn sites, some small porn sites make money from files you download to your machine without you aware that it's already downloaded.


        █████████████████      ███████████████    ██████████  ████████    █████████████
    █    ███████   ███████  ████████      █████  ███████████ ████████    ██████   ██████ 
        █████████   ███████  ████████      █████  ████████████████████  ████████   ▀▀▀▀▀▀
   ▅▅  ████████   ███████  ████████      █████  ████████████████████  ████████
  █  ▀▀  ████████████████    ████████      █████  ████████████████████    ██████████████
     ▅▅████████   ███████  ████████      █████  ████████████████████              █████   
       ▀▀████████   ███████  ████████      █████  ████████████████████  ▄▄▄▄▄▄      █████
▅▅▅▅▄ ████████   ███████  ████████      █████  ████████ ███████████  ▀▀██████████████
        █████████████████     ████████████████   ████████ ███████████    ▀▀▀██████████


Your Intro
Telegram Casino
to Fun & Entertainment
The Next-Gen
Gaming Space
     ▃▃▃▃▃▃▃▃▃▃▃▃▃
  ▄▄█████████████▄▄
██▀               ▀████▄
                       ██
   ██            ■■    ██
 ██████        ■■  ■■  ███
   ██    ▀ ▀     ■■    ███     
     ▃▃▃▃▃▃▃▃▃▃        ██
    █████████████      ██
    ██          ████████▀
████▀           ▀█████▀
zasad@ (OP)
Legendary
*
Offline Offline

Activity: 1750
Merit: 4273



View Profile WWW
August 25, 2022, 06:44:56 PM
 #12

https://twitter.com/kucoincom/status/1562301841529978883
"The #KuCoin security team has noticed a malicious Chrome web extension called Google Sheets which may replace your withdrawal address with the attacker's address when you try to make a transaction.
Please don't download any suspicious extensions, or click any suspicious links.⚠️"

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
albon
Legendary
*
Online Online

Activity: 1694
Merit: 1362



View Profile
August 26, 2022, 07:14:37 PM
 #13

https://twitter.com/kucoincom/status/1562301841529978883
"The #KuCoin security team has noticed a malicious Chrome web extension called Google Sheets which may replace your withdrawal address with the attacker's address when you try to make a transaction.
Please don't download any suspicious extensions, or click any suspicious links.⚠️"

Thank you for sharing this, there are many malicious extensions on Chrome browser and Firefox. Most of these extensions are not the original extension for the wallet or the exchange, but rather a fake extension with the same name, so everyone should be careful, the simple solution is to put important sites and their extensions in the bookmark and avoid Trust any messages that come on the mail because most of these messages contain links to fake sites.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!