Socket uncovered a cross-browser extension operation targeting cryptocurrency traders. Four malicious Chrome and Firefox extensions steal authenticated Axiom Trade and Padre session and wallet-related data, while two earlier extensions linked to the same publisher operation reveal a longer-running pattern of repackaging crypto trading tools. The Socket Threat Research team identified six Chrome and Firefox extensions linked through a combination of shared code, command and control (C2) infrastructure, publishing history, cloned crypto trading tools, marketplace artifacts, and specific targetin