Malicious Chrome Extension Steals MEXC Wallet Credentials and Automates Trading

A dangerous Chrome extension called MEXC API Automator has been discovered stealing cryptocurrency exchange credentials from unsuspecting users.

Socket’s Threat Research Team identified this malicious tool on the Chrome Web Store, where it remains available despite security warnings.

Published on September 1, 2025, by a developer using the alias jorjortan142, the extension claims to automate trading on the MEXC cryptocurrency exchange. However, it secretly creates API keys with hidden withdrawal permissions and steals the credentials.

MEXC AP Automator
MEXC AP Automator

When users visit MEXC’s API management page, the extension automatically selects all permission checkboxes, including the critical withdrawal option.

API management page
API management page

It then uses CSS manipulation to hide the checked state of the withdrawal permission, making it appear disabled in the user interface while keeping it active for the server.

After the user completes two-factor authentication, the extension extracts the newly generated API key and secret from the success modal. It then transmits these credentials to a Telegram bot controlled by the threat actor, enabling complete account takeover.

The attacker can execute trades, drain wallets, and withdraw funds without needing the victim’s password or bypassing security measures. The extension operates entirely within the browser, making it difficult for traditional security tools to detect.

The threat actor behind this scheme also operates under the SwapSushi brand, maintaining a social media presence and a Telegram bot for cryptocurrency swapping.

Analysis of the extension’s code reveals Russian language comments, indicating the developer is likely a Russian speaker. MEXC serves millions of users across 170+ countries, making this a significant threat to the global cryptocurrency community.

Know malware
Know Malware

Socket researchers recommend auditing browser extensions, removing potentially malicious tools, safeguarding API keys through regular rotation, and monitoring accounts for suspicious activity.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories