Odaily Planet Daily News SlowMist officially released an analysis of the Osiris malicious browser extension, which pointed out that the malicious browser extension will replace the user's normal download link and redirect to the download link of the malicious program. The user unknowingly downloads and installs the malicious program, resulting in the loss of encrypted assets. After obtaining the data, the attacker can try to decode and obtain the private key or mnemonic phrase of the Web3 wallet, thereby stealing the user's assets. The attacker can also obtain the account password saved in the user's Chrome, and then take over the user's social platform account, cryptocurrency platform account, etc. This type of extension disguised as a "security tool" steals encrypted assets and user data by hijacking download links, implanting malicious code, etc., and some users have suffered losses. In view of this, users are reminded to avoid installing unknown programs, extensions, etc., and do not trust strangers' solutions or tool recommendations.