MEXC API Automator malicious Chrome extension steals MEXC API keys
Malware Activity
Summary
Hide ▲
Show ▼
MEXC API Automator is a malicious Chrome extension that steals MEXC API keys from authenticated browser sessions and can give attackers control over reachable wallets and balances. It creates new keys with withdrawal permissions, hides that permission in the UI, and sends the Access Key and Secret Key to a hardcoded Telegram bot. Because the keys remain valid until revoked, the abuse can persist even after the extension is removed.
Related Happenings
Chrome Web Store malicious extensions coordinated campaign using shared C2
Campaign
H score38
First: 14.04.2026 23:33
Last: 14.04.2026 23:33
Sources 1
About this happening:
A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...
Chrome Web Store malicious extensions coordinated campaign using shared C2
CampaignAbout this happening: A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...
QuickLens - Search Screen with Google Lens hit by network compromise
Incident
H score57
First: 28.02.2026 21:18
Last: 28.02.2026 21:18
Sources 1
About this happening:
The QuickLens - Search Screen with Google Lens Chrome extension was compromised and used to push malware to about 7,000 users, creating risk of credential theft*...
QuickLens - Search Screen with Google Lens hit by network compromise
IncidentAbout this happening: The QuickLens - Search Screen with Google Lens Chrome extension was compromised and used to push malware to about 7,000 users, creating risk of credential theft*...
Fake AI assistant Chrome extension malware activity
Malware Activity
H score16
First: 16.02.2026 16:00
Last: 16.02.2026 16:00
Sources 1
About this happening:
A cluster of 30 malicious Chrome extensions posing as AI assistants is stealing email content and other sensitive data from Chrome users, creating a broad browser-...
Fake AI assistant Chrome extension malware activity
Malware ActivityAbout this happening: A cluster of 30 malicious Chrome extensions posing as AI assistants is stealing email content and other sensitive data from Chrome users, creating a broad browser-...
CL Suite Chrome extension stealing Meta Business data
Malware Activity
H score39
First: 13.02.2026 13:25
Last: 13.02.2026 13:25
Sources 1
About this happening:
The CL Suite Chrome extension is exfiltrating TOTP seeds, current 2FA codes, and Meta Business data from Meta Business Suite and Facebook Business Manager...
CL Suite Chrome extension stealing Meta Business data
Malware ActivityAbout this happening: The CL Suite Chrome extension is exfiltrating TOTP seeds, current 2FA codes, and Meta Business data from Meta Business Suite and Facebook Business Manager...
AiFrame malicious Chrome extension spraying operation
Malware Activity
H score16
First: 13.02.2026 13:25
Last: 13.02.2026 13:25
Sources 1
About this happening:
The AiFrame operation spread fake Chrome AI assistants that delivered malicious extensions, putting over 260,000 Google Chrome users at risk of credential theft, e...
AiFrame malicious Chrome extension spraying operation
Malware ActivityAbout this happening: The AiFrame operation spread fake Chrome AI assistants that delivered malicious extensions, putting over 260,000 Google Chrome users at risk of credential theft, e...
Timeline
-
13.01.2026 19:22 1 articles · 6mo ago
SwapSushiBot-linked YouTube channel created
Attribution UpdateA YouTube channel created on August 17, 2025, uses the same name referenced with jorjortan142 and helps support the operator infrastructure around the SwapSushiBot bot and related promotion channels.
Show sources
- Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool — thehackernews.com — 13.01.2026 19:22
-
13.01.2026 19:22 1 articles · 6mo ago
MEXC API Automator first published
Untyped PhaseA malicious Google Chrome extension named MEXC API Automator was first published on September 1, 2025, on the Chrome Web Store, where it posed as a trading helper for MEXC while requesting API-key generation and withdrawal-related permissions.
Show sources
- Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool — thehackernews.com — 13.01.2026 19:22
-
13.01.2026 19:22 2 articles · 6mo ago
Researchers disclose MEXC API key theft extension
Initial DisclosureCybersecurity researchers disclosed on January 13, 2026 that MEXC API Automator injects script.js into the authenticated MEXC API management page, creates new API keys, enables withdrawal permissions, hides that setting in the UI, and exfiltrates the Access Key and Secret Key to a hardcoded Telegram bot.
Show sources
- Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool — thehackernews.com — 13.01.2026 19:22
- Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool — thehackernews.com — 13.01.2026 19:22