Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data

Published September 9, 2026

Fake Chrome and Firefox extensions for crypto trading apps Axiom Trade and Padre secretly steal your login tokens, wallet info, and session data. Attackers then use that data to hijack your accounts.

Report priority
Medium
Targets
Chrome+1 more

How it works

  • Attackers created fake Chrome and Firefox extensions that look like real crypto trading tools.
  • When you install them, they secretly copy your login tokens, wallet details, and session data from Axiom Trade and Padre.
  • The extensions then send that stolen data to servers controlled by the attackers.
  • This lets them break into your crypto accounts and take control of your funds.

What to do

Check if you installed any of these extensions: J7Tracker, VREO, Orbit Tracker, or similar crypto trading tools. Look in your browser's extension list (Chrome: Extensions menu; Firefox: Add-ons and Themes). If you see any of these names, uninstall them immediately. If you used Axiom Trade or Padre, assume your session and wallet data may have been stolen.

Uninstall the extensions right away. Then check your Axiom Trade and Padre accounts for any unauthorized activity. If you see anything suspicious, change your passwords and enable two-factor authentication. Socket recommends monitoring your crypto wallets for unusual transactions. For more details, visit Socket's full report at socket.dev/blog/chrome-firefox-crypto-data-theft.

Technical details

Researchers at Socket Threat Research uncovered a cross-browser campaign targeting cryptocurrency traders using six malicious Chrome and Firefox extensions. Four extensions, J7Tracker, VREO (Chrome and Firefox versions), and Orbit Tracker, steal authenticated session data, wallet bundles, Firebase tokens, and browser cookies from users of Axiom Trade and Padre (now Terminal). The malicious modules in J7Tracker, VREO, and the Firefox version of VREO are byte-identical, automatically exfiltrating stolen data to threat actor-controlled Vercel deployments.

Orbit Tracker, introduced later, uses a separate collector but targets the same data (including sBundles, bundleKey, and authenticated user info) while reusing popup artifacts from J7Tracker. Two earlier extensions, GhostApe and GhostApe Color, were repackaged versions of the legitimate MockApe trading tool, sharing identical binaries and API references. All four Chrome extensions were removed in July 2026, J7Tracker and VREO for malware, the others for policy violations, before Orbit Tracker emerged in Firefox with different C2 infrastructure.

The campaign demonstrates a pattern of repackaging crypto trading tools to evade detection.