Fake AI Trading Bot Targets 7 Browser Wallet Extensions

A fake AI virtual asset trading software has been found distributing the malicious code 'Needle Stealer,' which steals browser wallet extension programs. The malware replaces legitimate extensions with malicious copies and extracts users' wallet credentials. HP revealed in a threat insight report published on July 17 that Needle Stealer was spread through fake AI trading agent websites. Attackers bypassed security detection by using legitimate Microsoft-signed software alongside malicious DLL files. HP explained the malware targeted seven browser wallet extensions, including Coinbase Wallet, MetaMask, and Phantom.
This method does not compromise Coinbase or MetaMask directly but replaces the user's installed extensions with malicious copies on their browsers.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 가짜 AI 거래봇, 브라우저 지갑 7종 노렸다