Talos Tracks Google Sheets Browser Skimmer Campaign

Cisco Talos says a monthslong campaign has moved into the browser, using the Google Visualization API and a public Google Sheets document to deliver obfuscated JavaScript that skims cryptocurrency deposit addresses in Chrome sessions. The lures pose as a leaked vulnerability report and target people around crypto trading forums and related communities. The trick is social engineering, not a device exploit. Victims are pushed to paste JavaScript into Chrome or install it through the Tampermonkey extension, and the injected code hooks the browser's fetch function so it can rewrite deposit addresses in page responses and in the clipboard, while also showing fake bonus elements. Because the malicious logic lives inside the browser session and can persist through Tampermonkey, ordinary web and endpoint controls may miss the tampering until a payment is already being redirected. For exchanges and financial firms that rely on browser-based deposit workflows, the exposure sits in user behavior and session trust, not just on the workstation.

Part of the PlainSec briefing for 2026-09-08

Editions

Sources