Security researchers have uncovered a malicious Google Chrome extension named Shitcoin Wallet that steals passwords and private keys from cryptocurrency wallets and portals.
What was Shitcoin Wallet meant for?
According to an introductory blog post, Shitcoin Wallet lets users connect to the Ethereum blockchain. Launched on December 9, the extension was designed to allow users to create their own wallet on the local terminals and communicate with other blockchain networks.
What is the new discovery?
Unlike its actual job, Shitcoin Wallet is found to contain malicious code, as informed by Harry Denley, Director of Security at the MyCrypto platform and reported by ZDNet.
According to the analysis of the malicious code, the process goes as follows:
Bottom line
The extension has around 621 installs and it is unclear if the developers of the Shitcoin Wallet are responsible for the malicious code or if the Chrome extension was compromised by a third-party.
Publisher