According to SlowMist's security monitoring system MistEye, a malicious Chrome MV3 extension is targeting TRON wallet users with phishing attacks designed to steal seed phrases, private keys, keystore files, and passwords. The extension uses Unicode obfuscation and brand impersonation to disguise itself as an official plugin, then loads a remote iframe popup page upon installation to trick users into entering sensitive information, which is transmitted via Telegram Bot.
The malicious infrastructure includes domains tronfind-api.tronfindexplorer.com and trx-scan-explorer.org. The extension ID is ekjidonhjmneoompmjbjofpjmhklpjdd. SlowMist advises users to uninstall the extension immediately and migrate assets if sensitive information has been submitted.