<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Osiris_Malicious_Browser_Extension_Malware_Link_Swap</id>
	<title>Osiris Malicious Browser Extension Malware Link Swap - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Osiris_Malicious_Browser_Extension_Malware_Link_Swap"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Osiris_Malicious_Browser_Extension_Malware_Link_Swap&amp;action=history"/>
	<updated>2026-07-26T11:14:16Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Osiris_Malicious_Browser_Extension_Malware_Link_Swap&amp;diff=6757&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/osirismaliciousbrowserextensionmalwarelinkswap.php}} {{Unattributed Sources}}  Osiris Browser Extension Logo/HomepageOsiris marketed itself as a cutting-edge Web3 browser extension offering powerful anti-scam protection, with a sleek interface and customizable features. However, investigations by cybersecurity firm SlowMist revealed that it is actually...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Osiris_Malicious_Browser_Extension_Malware_Link_Swap&amp;diff=6757&amp;oldid=prev"/>
		<updated>2025-05-28T23:48:29Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/osirismaliciousbrowserextensionmalwarelinkswap.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Osirisextension.jpg&quot; title=&quot;File:Osirisextension.jpg&quot;&gt;thumb|Osiris Browser Extension Logo/Homepage&lt;/a&gt;Osiris marketed itself as a cutting-edge Web3 browser extension offering powerful anti-scam protection, with a sleek interface and customizable features. However, investigations by cybersecurity firm SlowMist revealed that it is actually...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/osirismaliciousbrowserextensionmalwarelinkswap.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Osirisextension.jpg|thumb|Osiris Browser Extension Logo/Homepage]]Osiris marketed itself as a cutting-edge Web3 browser extension offering powerful anti-scam protection, with a sleek interface and customizable features. However, investigations by cybersecurity firm SlowMist revealed that it is actually a malicious tool designed to hijack download links, install malware, and steal sensitive user data including crypto assets and login credentials. Despite its claims of security, Osiris exploits trust to carry out targeted attacks, particularly on macOS users. The Web3 community, led by vigilant users like @0xmaoning and @Onefly_eth, played a key role in uncovering the threat. Though publicly exposed, Osiris remains available online, with little known about its operators or the fate of the stolen funds.&amp;lt;ref name=&amp;quot;slowmisttweet-19842&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;slowmistmedium-19843&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;osirishomepage-19844&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;osirisextension-19845&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Osiris Browser Extension ==&lt;br /&gt;
OSIRIS claims to be a robust browser extension developed to offer powerful anti-scam protection for Web3 users. Designed with aggressive security features and an intuitive interface, OSIRIS promises to help shield users from malicious online traps, ensuring a safe and secure browsing experience across multiple platforms. Its focus is on creating the strongest protection available in the Web3 ecosystem.&lt;br /&gt;
&lt;br /&gt;
The extension announces it will be available starting in June and is positioned as a critical tool for those active in decentralized web environments. OSIRIS emphasizes not just technical security but also user experience, aiming to align with users' personal styles and preferences through customizable themes like &amp;quot;Dark Spring Light&amp;quot; to &amp;quot;Set the Mood That Matches Your Vibe.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
OSIRIS is part of a broader initiative involving STR8FIRE, which is working on tokenizing entertainment, suggesting an intersection of cybersecurity and digital media innovation. Users can stay informed or seek support through contact options like email, Twitter, and Telegram.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
The unfortunate reality about the Osiris browser extension is that it is a malicious tool masquerading as a Web3 security solution, actively targeting users in the cryptocurrency space. Promoted as a safeguard against scams and phishing, Osiris is actually a carefully designed piece of malware that exploits users’ trust to compromise their devices and steal sensitive information, including cryptocurrency assets and login credentials.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
Osiris is a wolf in sheep’s clothing, using the language and aesthetic of security to deceive and exploit.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Osiris Malicious Browser Extension Malware Link Swap&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|May 22nd, 2025&lt;br /&gt;
|Fake Reviews Start Generating&lt;br /&gt;
|The start of fake reviews on the Osiris malicious browser extension.&lt;br /&gt;
|-&lt;br /&gt;
|May 28th, 2025 6:51:05 AM MDT&lt;br /&gt;
|Wolf In Sheep Clothing&lt;br /&gt;
|SlowMist posts a detailed article of their analysis on their Medium page.&lt;br /&gt;
|-&lt;br /&gt;
|May 28th, 2025 7:10:00 AM MDT&lt;br /&gt;
|SlowMist Tweet Posted&lt;br /&gt;
|SlowMist posts a tweet which links to their Medium article explaining the Osiris browser extension and associated malware, which users may install under the false belief that Osiris is enhancing their browser security.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
According to a detailed investigation by the cybersecurity firm SlowMist, Osiris manipulates browser behavior through Chrome’s declarativeNetRequest API. Once installed, it fetches network rules from attacker-controlled servers, dynamically modifying legitimate download links on trusted websites—like Notion—to instead deliver malware. While the user believes they are downloading a safe file, they are actually installing harmful software. This sleight of hand is made more dangerous by the extension’s ability to spoof download sources in Chrome’s interface, hiding its true intentions.&lt;br /&gt;
&lt;br /&gt;
The macOS variant of the malware, for example, disguises itself as a harmless installer that prompts users to drag it into the Terminal. This process secretly executes encoded commands that grant the malware elevated access. It then steals sensitive browser and keychain data, uploading it to attacker infrastructure. With this access, attackers can extract wallet keys, passwords, and potentially hijack the victim’s digital identity and assets.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
Specific figures detailing the total losses from Osiris-related incidents remain undisclosed.&lt;br /&gt;
&lt;br /&gt;
The total amount lost is unknown.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
After being alerted by user @0xmaoning, SlowMist investigated and confirmed that Osiris was a malicious extension posing as a Web3 security tool. It was found to silently replace legitimate download links with malware, tricking users into installing harmful software that could lead to the theft of crypto assets. SlowMist publicly warned users, highlighting the extension's deceptive tactics and urging increased vigilance.&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
The broader community, including key figures like @0xmaoning and @Onefly_eth, played a critical role in exposing the threat. SlowMist praised their contributions and used the incident to stress the risks of blindly trusting tools marketed as security solutions. They encouraged users to avoid unknown extensions, rely on reputable security tools, and stay informed to protect themselves in the volatile Web3 landscape.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There does not appear to be any available recovery for any users affected by the malware.&lt;br /&gt;
&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
Osiris is still generally available for download. Very little is known about who is behind the malware or what is happening with the stolen funds.&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;slowmisttweet-19842&amp;quot;&amp;gt;[https://twitter.com/SlowMist_Team/status/1927714174584705336 SlowMist - &amp;quot;Sometimes, solutions or tools that claim to enhance “security” may actually exploit the user’s trust to launch attacks. Today, @0xmaoning reached out to the SlowMist Security Team after spotting phishing behavior in the browser extension Osiris.&amp;quot; - Twitter/X] (Accessed May 28, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;slowmistmedium-19843&amp;quot;&amp;gt;[https://slowmist.medium.com/a-wolf-in-sheeps-clothing-analysis-of-the-osiris-malicious-browser-extension-890d03028691 A Wolf in Sheep’s Clothing: Analysis of the Osiris Malicious Browser Extension - SlowMist Medium] (Accessed May 28, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;osirishomepage-19844&amp;quot;&amp;gt;[https://osiris.vip/ Osiris Homepage - Do Not Download] (Accessed May 28, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;osirisextension-19845&amp;quot;&amp;gt;[https://chromewebstore.google.com/detail/osiris/leegjgppccbgnajpjgijlhplefgpnmdf/ Osiris Browser Extension - Chrome Web Store (Do Not Download)] (Accessed May 28, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>