HP Wolf Security found a fake AI crypto-trading assistant delivering Needle Stealer through a malicious ZIP file and replacing seven browser wallet extensions on infected Windows computers. The campaign used search-engine poisoning and paid ads to promote tradingclaw[.]pro, with the activity covered in HP's September threat report based on threats observed from April through June 2026.
Why it matters
The installer used a legitimate, digitally signed Microsoft OLEView executable to help bypass SmartScreen, while a malicious DLL loaded the stealer through process hollowing. Needle Stealer checked Chromium extension IDs for Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask and Tonkeeper.
After finding a target, the malware shut down the browser and inserted a counterfeit extension into the existing folder. The replacement connected to attacker-controlled infrastructure, loaded backup domains and displayed realistic wallet login screens designed to capture credentials. HP said the operation began with a compromised endpoint, not a breach of Coinbase, MetaMask or their official extensions.
Market impact
The campaign creates a direct security risk for users who download unverified AI trading tools, particularly when search ads make a malicious installer appear legitimate. Malwarebytes previously documented the TradingClaw campaign and linked Needle Stealer to other malware loaders, indicating that the fake assistant was one delivery route within a broader operation.
HP did not disclose a campaign-wide victim count or aggregate crypto-loss figure. Users should treat unofficial wallet software and AI trading assistants as high-risk downloads, verify extension publishers and avoid entering wallet credentials into a replacement interface on a compromised device.
Frequently asked questions
-
How did the fake AI trading tool infect Windows computers?
Attackers promoted tradingclaw[.]pro through search poisoning and paid ads. Victims downloaded a ZIP containing a trusted-looking OLEView executable and a malicious DLL that loaded Needle Stealer.
-
Which wallet extensions did the malware target?
Needle Stealer checked for Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask and Tonkeeper.
-
How did the malware replace browser wallet extensions?
It identified targeted Chromium extensions by their 32-character IDs, shut down the browser and inserted a malicious extension into the existing extension folder.
-
Was Coinbase or MetaMask officially breached in this campaign?
No. HP described the incident as a compromise of an infected Windows endpoint, not a breach of Coinbase, MetaMask or their official extensions.
-
Did HP report how much crypto was stolen?
No. HP did not disclose a campaign-wide victim count or aggregate crypto-loss figure.
CryptoSlate