We have already seen many creepy browser extensions for Chrome in past inserting ads or tracking user’s browsing activities without consent, but this extension has gone one step further and stealing users’ Bitcoins.
Reddit user vin_dog reports that the “Cryptsy Dogecoin Live Ticker” extension available in Google’s Chrome Web Store is stealing users’ Bitcoins, by changing Bitcoin wallet address. It simply replaces user’s wallet address with its own address, and hence the transaction amount goes to the account of the developer (of this extension).
The above extension is still available in Chrome Web Store, and many other users have reported this issue in extension’s review section. Well, just to remind you, Google doesn’t review extensions and apps hosted on its official add-on store.