Researchers at SlowMist have flagged a new malware strain called KREMLIN that’s targeting Chrome and Edge browser extensions to steal passwords, session tokens, and other sensitive data. According to their report, these rogue extensions can get installed without any user approval, sidestepping Chromium's built-in security protections.
How KREMLIN Works
KREMLIN zeroes in on harvesting sensitive browser data. It abuses the manifest files of Chrome and Edge extensions to access session content and login credentials. What’s especially nasty: the malware can install itself without any obvious prompts, making it tough to spot and remove in time.
Why Ethereum Is in the Mix
The attackers are leveraging Ethereum smart contracts to dynamically update the addresses of their command-and-control (C2) servers and malware download sources. This on-chain tactic lets them rotate their infrastructure on the fly, without relying on traditional domains or hosting. The result? A campaign that’s way harder to shut down or block.
What This Means for the Ecosystem
Using Ethereum smart contracts to manage botnet and malware infrastructure raises the bar for defenders: static IOCs become obsolete fast, and takedowns have to account for on-chain logic. The main attack vector is browser extensions and their session data access, so locking down extension installs and policies is now mission-critical for both corporate and home setups.
