|

Fake AI crypto software is secretly replacing browser wallet extensions

Six-step diagram showing how a fake AI trading tool delivered Needle Stealer and replaced browser crypto wallet extensions with credential-stealing copies.

HP Wolf Security, the corporate’s threat-research group, mentioned a faux AI crypto-trading assistant distributed malware that might change browser crypto wallet extensions on an contaminated Windows laptop and switch the acquainted wallet interface right into a credential lure.

The marketing campaign appeared in HP’s September threat report, revealed Sept. 17 and primarily based on threats noticed from April via June 2026. HP described a compromise that started on a consumer’s endpoint after a counterfeit trading tool was downloaded and run, not a breach of Coinbase, MetaMask, or their official extensions.

Malwarebytes had documented the TradingClaw campaign in April and located that Needle Stealer additionally circulated via different malware loaders. The faux AI assistant was one route right into a broader malware operation.

Related Reading

Hackers sneak crypto wallet-stealing code into a popular AI tool that runs every time


Attackers promoted tradingclaw[.]professional as an AI assistant that might comply with a personalised technique and commerce across the clock, in line with the full HP report. Search-engine poisoning and paid ads directed potential victims to a ZIP file offered because the software’s installer.

The archive contained an executable named Trading Agent.exe and a DLL named iviewers.dll. HP recognized the executable as OLEView, Microsoft’s official, digitally signed OLE/COM Object Viewer. HP mentioned the signed program helped bypass Microsoft’s SmartScreen popularity test, whereas the malicious payload remained within the accompanying DLL.

Running the trusted-looking program brought about it to load that DLL. The code then decrypted Needle Stealer and used course of hollowing, a method that runs malicious code inside a newly launched official course of.

Six-step diagram showing how a fake AI trading tool delivered Needle Stealer and replaced browser crypto wallet extensions with credential-stealing copies.
A faux AI buying and selling device delivered Needle Stealer via a malicious ZIP, focusing on seven wallet extensions and stealing credentials from compromised units.

How the crypto wallet swap labored

Needle Stealer enumerated Chromium browser extensions and checked their 32-character IDs towards a hardcoded record protecting Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper.

When it discovered a goal, the malware shut down the browser and extracted a corresponding malicious extension into the present extension folder.

On its first launch, the substitute related to a command-and-control server utilized by the attacker and loaded backup domains. HP mentioned the attackers had constructed sensible login screens, and a crypto wallet ID and password entered right into a counterfeit interface could possibly be despatched to the operator.

MetaMask’s guidance says that, for crypto wallets created with a Secret Recovery Phrase, the password unlocks MetaMask regionally and can’t restore the wallet elsewhere. Even so, the substituted extension was working on an already compromised gadget, leaving regionally accessible funds in danger.

Neither HP’s report nor its newsroom summary disclosed a campaign-wide sufferer rely or combination crypto-loss determine, leaving the operation’s scale unknown.

The publish Fake AI crypto software is secretly replacing browser wallet extensions appeared first on CryptoSlate.

Similar Posts