Security researchers reported a malicious Google Chrome extension, MEXC API Automator (pppdfgkfdemgfknfnhpkibbkabhghhfh), masquerading as a trading-automation tool for the MEXC cryptocurrency exchange. Published to the Chrome Web Store on 2025-09-01 by an actor using the alias "jorjortan142", the extension targets users who visit MEXC’s API key management page (/user/openapi) and runs a content script (script.js) inside the already-authenticated browser session to create new API keys.
The extension is designed to enable withdrawal permissions on the newly created keys while hiding that capability in the UI, then exfiltrates the API key and secret to a hardcoded Telegram bot controlled by the attacker. With these credentials, the actor can take programmatic control of affected accounts to execute trades and automate withdrawals, potentially draining balances reachable via MEXC. Socket stated the extension remained live on the Chrome Web Store at the time of reporting and that they notified Google; The Hacker News amplified the findings and noted the extension had limited observed downloads but could still enable direct financial theft from compromised accounts.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting stated that the malicious extension was still available on the Chrome Web Store at the time of disclosure, with one report noting it had 29 downloads. Researchers warned that stolen API keys could continue to provide account access even after the extension was removed unless the keys were revoked.
In its report, Socket said it had flagged the extension as malware and notified Google, while also linking the publisher handle 'jorjortan142' to 'SwapSushi'-branded social accounts, a Telegram bot, and related infrastructure. Researchers also noted Russian-language code comments, suggesting a Russian-speaking developer, though without firm country-level attribution.
Socket's Threat Research Team discovered that the extension automatically created new MEXC API keys in logged-in browser sessions, enabled broad permissions including withdrawals, hid the withdrawal permission in the UI, and exfiltrated the access key and secret to a hardcoded Telegram bot. The stolen credentials could let attackers trade and withdraw funds without needing passwords or bypassing 2FA.
A Chrome extension named 'MEXC API Automator,' published by 'jorjortan142,' was added to the Chrome Web Store while posing as an automation tool for the MEXC cryptocurrency exchange. It was later identified as malware designed to abuse authenticated MEXC sessions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.