19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
19 Chrome and Edge extensions found with crypto-draining code.
Summary
Cybersecurity researchers have identified 19 malicious browser extensions, 18 for Chrome and one for Edge, published over the last six months. These extensions, tracked under the name 'Superior', steal wallet secrets and drain cryptocurrency. The threat actor either acquires legitimate extensions or publishes clean versions, later updating them with malicious code once they gain user downloads.
Full text
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code Ravie LakshmananAug 28, 2026Web Security / Supply Chain Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active since February 2024. Socket is tracking the activity under the name Superior. The modus operandi is relatively straightforward: the threat actor either acquires legitimate extensions with proper functionality or pushes a clean version that's devoid of any malware. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published. Of the identified extensions, 14 were created by the threat actor, while the remaining five were purchased from their previous owners. The complete list of extensions is below - Extensions bought by the threat actor koccklolohdacbfooifnpebakpbeipc - Enable Right Click & Copy — Smart Unlock + OCR fegckejpfnlmfgkfjpinlbgmeeijjkel - RapidLens - Google Lens for Screen Search & Images kdenlnncndfnhkognokgfpabgkgehodd - QuickLens - Search Screen with Google Lens jamminefolhgepgihbmcjjhgldbfcikp - Password Protect PDF inmkjedjdhgpknjogbjomhnbgdccckkg - Allow Copy - Select & Enable Right Click (Microsoft Edge) Extensions created and published by the threat actor - fcgdejjichpgfaaafflplhfijcnieopb - PixelCheck cfpnjdbpojpcongfaefcamjbaolpelcd - Creative Library - Ad Spy Tool aapdalkmclfaahehnmicbglkohkldhne - Website Traffic Checker: MirrorSphere SEO Stats dkdadldmiefjldmegbjbnhhfddnkhlhm - Site Signal - Website Traffic & SEO Checker fjmlhlkccegopebcllcmafahkmeejpph - SEO Pulse Pro - Website Traffic & SEO Analyzer iekoapohahgmogbagegmcgplbkikcgke - Private Crypto News Reader ahpnnnjbnfbhoikhohglpohnoocjcoco - Blockfolio: Address Monitor oeacadlaclegkkkdehjmiifnjhcekclj - Crypto Rates & Fiat Converter jmlgannjlbliikgcaieomgmcnfplglea - Crypto Alerter: Price Alarms & Volatility Warnings lhmcajhgadanidbopgaoobjlldegjmke - DeFi Pulse Tracker gfackggoapepdmnjnkblogdcjpgcjiak - Crypto Price Badge: Quick Glance hfijkbdkpidafdbeebnnkhfccildbcle - Multi-Chain Explorer cngchfbfgejllcbhmeadjhiebebiome - LedgerLook: Wallet Checker aodkjdeghbjiaienipfjkbpcikkacbcp - Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray It's worth highlighting that the "QuickLens - Search Screen with Google Lens" was previously flagged by both Annex Security and monxresearch-sec earlier this year, detailing its ability to push malware to downstream customers, inject arbitrary code, and harvest sensitive data. The latest findings from Socket suggest that the activity is broader in scope than previously thought and has been ongoing since February 2024. Some aspects of this campaign were documented by DomainTools Investigations in May 2025. At the time, the threat actor was observed creating fake websites masquerading as legitimate services, productivity tools, ad and media creation or analysis assistants, VPN services, cryptocurrency or banking utilities to trick users into installing malicious extensions from the Chrome Web Store. "The extensions typically have a dual functionality, in which they generally appear to function as intended, but also connect to malicious servers to send user data, receive commands, and execute arbitrary code," DomainTools Investigations said. The extension with the most potential impact is "Enable Right Click & Copy — Smart Unlock + OCR," which has a collective install base of 80,000 users across both Chrome and Edge browsers. Each of the extensions also supports the ability to establish contact with a command-and-control (C2) server and set up a persistent WebSocket connection. "Worth noting is that the loading framework supports rotation of the C2 endpoint based on instructions received from the initial C2 server and this behavior has been observed in the wild," Zanki explained. "That functionality enables threat actors to distribute victims to different groups and dedicated C2 infrastructure and to reduce the detection risk. Data exfiltration endpoint is also dynamically received from the C2 instructions enabling a per-victim exfiltration channel." As observed in the case of QuickLens, the malicious code embedded in the extensions strips Content Security Policy (CSP) headers from every page and facilitates the injection of JavaScript code modules on targeted websites using content scripts. A total of 16 modules have been identified. They span the following categories - Multi-chain wallet drainer Hardware-wallet seed-phrase harvester Cryptocurrency exchange and wallet account harvester Universal credential or form grabber Facebook and LinkedIn account stealers Browser history stealer ClickFix-style lure The ClickFix module injects a fake web browser update and employs operating system-specific instructions to get the user to copy and paste the malicious command. Exactly who is behind the campaign remains unknown. But the fact that they have been successfully operating for more than two years points to a "very capable threat actor." "The biggest risk for end-users is the operational technique in which the threat actor successfully acquires legitimate extensions and releases new versions empowered with malicious functionality," Zanki said. "That approach, combined with Chrome's default extension update settings, performs auto-updating to the latest version of extension, providing the threat actor with a powerful vector to maximize the impact and reach of the extension acquisition." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE cryptocurrency, Malware, Supply Chain, Web Security ⚡ Top Stories This Week Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor Attackers Exploit VMware vCenter Vulnerability to Gain Persi