Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareUsed by 1 actor

MEXC API Automator

MEXC API Automator is a malicious Google Chrome extension targeting users of the MEXC cryptocurrency exchange. It masquerades as a tool for automating trading or simplifying MEXC API key management, but is designed to hijack victim accounts and enable theft of funds. The extension was reported by Socket’s Threat Research Team and identified as malware.

The extension is described as a Manifest V3 Chrome extension distributed through the Chrome Web Store, published on September 1, 2025, by the developer alias "jorjortan142." Its extension ID is pppdfgkfdemgfknfnhpkibbkabhghhfh. It injects a content script named script.js into MEXC API management pages matching ://.mexc.com/user/openapi* and activates when the victim is already authenticated to MEXC.

Its core behavior is to programmatically create new MEXC API keys inside the victim’s authenticated browser session, select permissions including withdrawals, and then manipulate the MEXC user interface so the withdrawal permission appears disabled even though it remains enabled server-side. Reported UI tampering includes removing the visual checked state from the withdrawal checkbox, hiding the tick mark with injected CSS, and using a MutationObserver to keep the permission visually hidden if the site restores it.

After MEXC displays the newly generated credentials, the extension extracts the Access Key and Secret Key from the page and exfiltrates them via HTTPS POST requests to the Telegram Bot API using a hardcoded bot token and chat ID controlled by the threat actor. Reported exfiltration details include the Telegram endpoint api.telegram.org, bot token 7534112291:AAF46jJWWo95XsRWkzcPevHW7XNo6cqKG9I, and chat ID 6526634583.

The attack does not require theft of the user’s password and does not bypass 2FA; instead, it abuses the victim’s existing authenticated session and waits for normal user completion of any required 2FA during API key creation. With the stolen API credentials, the threat actor can gain programmatic control of the victim’s MEXC account, execute trades, and perform automated withdrawals. The risk can persist after the extension is removed because the created API keys remain valid until revoked.

High-confidence attribution in the reporting is limited. Socket reported Russian-language inline comments in the code and assessed with moderate confidence that the operator is a Russian speaker. The activity was also linked in reporting to a broader crypto-focused threat cluster associated with the "SwapSushi" brand and the handle "jorjortan142," but country-level attribution was not established. The malware specifically targets cryptocurrency exchange users, particularly MEXC users managing API keys for bots or automated trading.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
jorjortan142

A malicious Chrome extension called MEXC API Automator is abusing trust in browser add-ons to steal cryptocurrency trading access from MEXC users.

via cyber security newscybersecuritynews.com
INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 days ago
uri●●●●●●●●●●●●View more in app6 months ago
ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

security online infoNews
Jan 14, 2026
Malicious Chrome Extension Drains Crypto via Secret API Keys

A malicious Chrome extension published on the Chrome Web Store that abuses an authenticated MEXC session to programmatically create new API keys, enable withdrawal permissions while hiding them in the UI, and exfiltrate the API key/secret to a hardcoded Telegram bot so the actor can drain funds.

Read more
the hacker newsNews
Jan 13, 2026
Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool

A malicious Google Chrome extension that targets MEXC users by injecting a content script into the authenticated MEXC API management page, creating new API keys with withdrawal permissions, hiding the withdrawal permission in the UI, and exfiltrating the Access Key/Secret Key to an attacker-controlled Telegram bot. The stolen keys can enable account takeover actions such as trading and withdrawals even after the extension is uninstalled (until keys are revoked).

Read more
cyber security newsNews
Jan 13, 2026
Malicious Chrome Extension Steals Wallet Login Credentials and Enables Automated Trading

A Manifest V3 Chrome extension that activates on MEXC’s API management page, silently enables high-privilege API key permissions (including withdrawals) via UI deception, scrapes newly created Access/Secret keys from the DOM, and exfiltrates them to attacker-controlled Telegram infrastructure to enable account takeover and fund theft without stealing passwords.

Read more
socket blogNews
Jan 12, 2026
Malicious Chrome Extension Steals MEXC API Keys for Account Takeover

A malicious Manifest V3 Chrome extension that runs on MEXC’s /user/openapi page to automate creation of new MEXC API keys with trading + withdrawal permissions, deceptively hides the withdrawal permission state in the UI, then steals (access key + secret key) from the success modal and exfiltrates them via HTTPS to a hardcoded Telegram Bot API endpoint, enabling account takeover and financial theft via API-based trading/withdrawals.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.