Malicious Chrome and Edge Extensions Pilfer Crypto Wallets and User Data
A new cluster of 19 malicious browser extensions for Google Chrome and Microsoft Edge has been uncovered, actively engaged in stealing cryptocurrency wallet secrets and draining funds. This sophisticated campaign, tracked as 'Superior,' has been operational since at least February 2024, leveraging a deceptive strategy of acquiring legitimate extensions or pushing clean versions before injecting malicious code.
Cybersecurity researchers have identified a cluster of 18 **Google Chrome** and one **Microsoft Edge** extensions that were published over the last six months, harboring wallet secret-stealing and cryptocurrency-draining capabilities.
According to **Socket** security researcher **Karlo Zanki**, the extensions share similarities in code and tradecraft, with evidence suggesting the campaign, dubbed 'Superior' by Socket, may have been active since February 2024.
### Deceptive Tactics: From Legitimate to Malicious
The threat actor's modus operandi is straightforward yet effective: they either acquire legitimate extensions with existing functionality or publish a clean, malware-free version. Once these extensions gain a significant user base, a new version containing the malicious behavior is pushed as an update.
Of the identified extensions, 14 were initially created by the threat actor, while the remaining five were purchased from their previous owners. The full list includes:
**Extensions bought by the threat actor:**
* `koccklolohdacbfooifnpebakpbeipc` - Enable Right Click & Copy β Smart Unlock + OCR
* `fegckejpfnlmfgkfjpinlbgmeeijjkel` - RapidLens - Google Lens for Screen Search & Images
* `kdenlnncndfnhkognokgfpabgkgehodd` - QuickLens - Search Screen with Google Lens
* `jamminefolhgepgihbmcjjhgldbfcikp` - Password Protect PDF
* `inmkjedjdhgpknjogbjomhnbgdccckkg` - Allow Copy - Select & Enable Right Click (**Microsoft Edge**)
**Extensions created and published by the threat actor:**
* `fcgdejjichpgfaaafflplhfijcnieopb` - PixelCheck
* `cfpnjdbpojpcongfaefcamjbaolpelcd` - Creative Library - Ad Spy Tool
* `aapdalkmclfaahehnmicbglkohkldhne` - Website Traffic Checker: MirrorSphere SEO Stats
* `dkdadldmiefjldmegbjbnhhfddnkhlhm` - Site Signal - Website Traffic & SEO Checker
* `fjmlhlkccegopebcllcmafahkmeejpph` - SEO Pulse Pro - Website Traffic & SEO Analyzer
* `iekoapohahgmogbagegmcgplbkikcgke` - Private Crypto News Reader
* `ahpnnnjbnfbhoikhohglpohnoocjcoco` - Blockfolio: Address Monitor
* `oeacadlaclegkkkdehjmiifnjhcekclj` - Crypto Rates & Fiat Converter
* `jmlgannjlbliikgcaieomgmcnfplglea` - Crypto Alerter: Price Alarms & Volatility Warnings
* `lhmcajhgadanidbopgaoobjlldegjmke` - DeFi Pulse Tracker
* `gfackggoapepdmnjnkblogdcjpgcjiak` - Crypto Price Badge: Quick Glance
* `hfijkbdkpidafdbeebnnkhfccildbcle` - Multi-Chain Explorer
* `cngchfbfgejllcbhmeadjhiebebiome` - LedgerLook: Wallet Checker
* `aodkjdeghbjiaienipfjkbpcikkacbcp` - Meta & Facebook Ad Library Spy β Save Ads, Finder, Downloader | FeedX-Ray
It's important to note that "QuickLens - Search Screen with Google Lens" was previously flagged by both **Annex Security** and **monxresearch-sec** earlier this year for its ability to push malware, inject arbitrary code, and harvest sensitive data.

### Broader Scope and Persistent Threat
Socket's latest findings indicate a broader scope of activity than previously understood, with some aspects of this campaign documented by **DomainTools Investigations** in May 2025. At that time, the threat actor was observed creating fake websites masquerading as legitimate services to trick users into installing malicious extensions from the **Chrome Web Store**.
"The extensions typically have a dual functionality, in which they generally appear to function as intended, but also connect to malicious servers to send user data, receive commands, and execute arbitrary code," **DomainTools Investigations** stated.
One extension, "Enable Right Click & Copy β Smart Unlock + OCR," boasts a collective install base of 80,000 users across both Chrome and Edge, highlighting the potential impact. Each malicious extension is capable of establishing contact with a command-and-control (C2) server and setting up a persistent WebSocket connection.
"Worth noting is that the loading framework supports rotation of the C2 endpoint based on instructions received from the initial C2 server and this behavior has been observed in the wild," **Zanki** explained. "That functionality enables threat actors to distribute victims to different groups and dedicated C2 infrastructure and to reduce the detection risk. Data exfiltration endpoint is also dynamically received from the C2 instructions enabling a per-victim exfiltration channel."

### Diverse Malicious Modules
The malicious code embedded in the extensions strips **Content Security Policy (CSP)** headers from every page, facilitating the injection of JavaScript code modules on targeted websites using content scripts. A total of 16 modules have been identified, spanning various attack categories:
* Multi-chain wallet drainer
* Hardware-wallet seed-phrase harvester
* Cryptocurrency exchange and wallet account harvester
* Universal credential or form grabber
* **Facebook** and **LinkedIn** account stealers
* Browser history stealer
* **ClickFix**-style lure, which injects a fake web browser update and employs operating system-specific instructions to trick users into copying and pasting malicious commands.
### A Capable Threat Actor
The identity of the group behind this campaign remains unknown, but their successful operation for over two years points to a "very capable threat actor." The biggest risk to end-users stems from the operational technique of acquiring legitimate extensions and leveraging Chrome's default auto-update settings to push malicious versions, maximizing impact and reach.