GoPlus has issued a security alert regarding a malicious Chrome extension that poses as an Ethereum (ETH) wallet. Released on November 12, 2024, this extension deceptively advertises itself as a simple and secure wallet but contains a backdoor that encodes users' mnemonic phrases into Sui transactions. The extension then broadcasts these transactions from an attacker-controlled Sui wallet, effectively stealing user assets. Despite its stealthy nature, the extension remains available on the Chrome Web Store. GoPlus has reported the issue to Chrome and blocked the download link to prevent further downloads. The malicious extension is named "Safery: Ethereum Wallet," and the attacker's email is kifagusertyna@gmail.com.