Proprietary ·
MEGA Chrome extension stole credentials
Attackers used MEGA's Chrome Web Store account to publish extension v3.39.4. The update requested broader permissions and stole credentials and wallet secrets.
The MEGA compromise was fast and public. On 2018-09-04 at about 14:30 UTC, an attacker accessed MEGA's Chrome Web Store developer account and uploaded version 3.39.4 of the official extension.
The malicious build asked for expanded permissions. Once installed or auto-updated, it could read credentials entered on sites such as Google, GitHub, Amazon, and cryptocurrency services including MyEtherWallet, MyMonero, and IDEX.
The extension exfiltrated captured data to megaopac.host, an attacker server reported in Ukraine. The prize was not only passwords; wallet private keys and exchange credentials made the browser extension a direct path to cryptocurrency theft.
MEGA replaced the extension with a clean release the same day and warned users to change passwords and rotate wallet secrets. This record tracks the Chrome Web Store package, not MEGA's cloud-storage service itself.
Appendix · Affected releases
- Extension id corrected on 2026-09-02 after crx4chrome resolved each id to its listing: bigefpfhnfcobdlfbedofhhaibnlghod is MEGA, nlbmnnijcnlegkjjpcfjclmcfggfefdm is MyEtherWallet CX.
- The malicious CRX is not held and is unlikely to surface: Google pulled 3.39.4 about five hours after it was published on 2018-09-04 and no archive of the Chrome Web Store binary survives.
- What is held instead, recovered 2026-09-02, is the content script and manifest match list as the analysing researcher published them. They are transcriptions, so they are verification_material rather than served bytes.
- The code polls every two seconds for MyEtherWallet private keys via Angular scope, MyMonero view and spend keys, and Idex localStorage state, forwarding each to the extension background, which reached megaopac.host.
References
- MEGA Chrome Extension Hacked - Detailed Timeline of Eventsserhack.me
- Hackers replace MEGA Chrome extension with trojanized versionsecurityboulevard.com
- MEGA Chrome extension hacked, cryptocurrency and user passwords targetedbleepingcomputer.com
Source record: proprietary/mega-chrome/meta.yaml