HP’s threat research team disclosed a malware campaign, active between April and June 2026 and reported September 17, 2026, in which attackers built a fraudulent website advertising a fake AI-powered crypto trading agent. Visitors who downloaded the tool were infected with a credential-stealing malware family HP calls Needle Stealer, delivered via a Microsoft-signed executable that used DLL side-loading and process hollowing to inject malicious code into browser wallet extensions. The malware silently replaced victims’ browser wallets — including MetaMask, Coinbase Wallet, and Phantom — with lookalike versions that sent wallet passwords back to the attackers, enabling theft of any funds inside. No total financial loss was disclosed.