Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
ValleyRAT Backdoor Hidden in Adware Targets China and India
August 31, 2026
EU Designates ChatGPT a Very Large Online Platform After Reaching 45 Million Users
August 31, 2026
Brave Launches Email Aliases for Enhanced User Privacy
August 31, 2026
Home/Threats/Malicious Chrome and Edge Extensions Steal Crypto Wallets and Passwords
Threats

Malicious Chrome and Edge Extensions Steal Crypto Wallets and Passwords

Key Takeaways A sophisticated malware campaign, dubbed “Superior,” compromised 19 browser extensions across Google Chrome and Microsoft Edge. The attackers acquired legitimate extensions...

Marcus Rodriguez
Marcus Rodriguez
August 31, 2026 4 Min Read
3 0

Key Takeaways

  • A sophisticated malware campaign, dubbed “Superior,” compromised 19 browser extensions across Google Chrome and Microsoft Edge.
  • The attackers acquired legitimate extensions and injected malicious code via routine updates, affecting up to 80,000 users.
  • The malware primarily targets cryptocurrency wallets, aiming to steal seed phrases, drain funds, and capture session data from exchanges like Coinbase and Binance.
  • Beyond crypto, the extensions can steal passwords, browsing history, and social media data through a flexible, modular framework.
  • Users are urged to review installed extensions, remove unneeded ones, and change sensitive credentials if they suspect compromise.

A recent analysis has uncovered a widespread malware operation leveraging 19 popular browser extensions to illicitly obtain cryptocurrency wallet information, passwords, and other sensitive user data. The compromised extensions, initially appearing as benign utilities such as search enhancers, price trackers, and copy-unlocking tools, were later updated with stealthy malicious code.

Table Of Content

  • Key Takeaways
  • Details of the Superior Campaign
  • Wallet Drainers and Password Theft

The campaign specifically targeted 18 extensions available for Google Chrome and one for Microsoft Edge. Attackers employed a deceptive strategy: they acquired existing, trusted add-ons with established user bases. Subsequent automatic updates then delivered the harmful functionalities, exploiting the trust users had in the original developers. Two of these compromised extensions alone had a potential reach of 80,000 users.

Researchers at Socket.dev identified this operation, naming it “Superior” based on internal labels found within its JavaScript modules. According to a report from Socket.dev, the primary objective of this campaign is to facilitate wallet theft and drain cryptocurrency. However, the malware is also capable of exfiltrating login credentials, session tokens, and browsing history.

This discovery highlights a critical vulnerability in the browser extension ecosystem: an extension’s initial legitimacy does not guarantee its ongoing safety. The practice of injecting malicious code into otherwise familiar tools through post-publication updates creates a significant risk, mirroring concerns raised in past compromised Chrome extension campaigns.

Details of the Superior Campaign

Socket researchers determined that 14 of the compromised extensions were developed by the threat actors themselves, while five were reportedly purchased from their original, legitimate developers. This strategy of introducing clean initial releases to build user trust, followed by malicious updates, makes it difficult for users to detect when an extension’s ownership has changed and its security posture has been compromised.

One of the most widely used affected extensions was “Enable Right Click & Copy – Smart Unlock + OCR.” While Google has since removed its Chrome version, the corresponding Edge version remained active and continued to deliver malware at the time of the research publication. This highlights a critical point: the removal of an extension from one store does not automatically uninstall it from users’ browsers or prevent a related version from operating on another platform.

The malware operates by establishing an encrypted WebSocket channel to attacker-controlled infrastructure. This channel is used to download and execute various code modules designed for specific malicious tasks. The system is also resilient, capable of switching to alternative command-and-control (C2) servers and using separate destinations for exfiltrated data. This modular and adaptive design allows the attackers to modify the malware’s behavior without requiring a new, visibly distinct extension version.

A key technique employed by the malware involves removing the browser’s Content Security Policy (CSP) header from visited web pages. The CSP is a vital security mechanism that limits the scripts a website can load, thereby preventing cross-site scripting (XSS) attacks. By bypassing this safeguard, the malicious extension can inject arbitrary code into web pages and activate it through hidden elements, a tactic reminiscent of other malicious Chrome security bypasses.

Wallet Drainers and Password Theft

The modules downloaded by the “Superior” malware are designed to target several high-value data types. A dedicated wallet drainer module identifies Ethereum Virtual Machine (EVM), Solana, and Tron wallets. It then maliciously replaces legitimate “Connect Wallet” or “Swap” button functionalities with requests controlled by the attackers. Another module employs convincing fake recovery or update screens to trick users into divulging their seed phrases, which would grant attackers full control over their cryptocurrency wallets.

Beyond direct wallet compromise, other modules focus on extracting data from active exchange and wallet sessions. This includes harvesting cookies, access tokens, profile details, and account balances from popular services such as Coinbase, Binance, Kraken, and MetaMask.

A universal form grabber embedded within the malware records text, email addresses, and password fields across all websites visited by the victim. This broad data collection capability extends the threat beyond cryptocurrency, potentially exposing personal accounts and even corporate login credentials.

The campaign also incorporates social media data theft, comprehensive browsing history collection, and deceptive browser update prompts. These fake prompts can copy an attacker-supplied command to the clipboard and instruct the victim to paste it into their computer, a dangerous tactic for gaining further system access. Such unexpected update instructions should always be treated with extreme suspicion, especially when a website requests command execution, as seen in recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/0dead0e4-b369-44d4-8fe9-f71ea76e0d7b/19-Chrome-and-Edge-Extensions-Caught-Stealing-Crypto-Wallets-and-Passwords.pdf?AWSAccessKeyId=ASIA2F3EMEYETJ3FO3CA&Signature=g6ikjeZPD4at5OlXpQT%2BJuajFtI%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCsTiGPi5CFyYGYYuy367pRR8TlskT1u2scm3CAvcEChgIhAJMckSokQcsmuJMQDt7RLh7ZS5%2B5TJJgph0ny55o6P66KvwECJT%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwKzIIhDs8oPiVsnRkq0ARVvf7HI1iO%2BEBNskA9smBUTpK4Id8DVcRrbpHVEJLl3CKQTvWk4kwCMQtpMKlL%2B5e4OZIHvLy8k8MIFlUy5PR4erhVfyABxd06NV1WX8vJy5t5C3g5fmUauqIEXGRN%2F5KvlxVpLCzxtupsEkkS60TrbCmeQnQfqlceKtKIzgddjUBibmMqvS3QAih9KwjcMJDxyyg9Gw27Qv2RhFPWk69m4COtuRc63rXbu9fiZEjUbyNkWbwDnQ9VubifNwgDHnNVqbFmGwcewIaoODhvwjPoZnoc0B2EMKwLeUWjl1NN4E6mXgylyRQJRG6OJfPiHTbp%2Bm%2BmHoIBYe5FlPiyBFa9FxK67sQy2VVafkrArUAy9lhYRwhql6%2FZOxaJC7s7HJpIKZT7KCB9NrhXmtZM1

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Ethereum Blockchain Used to Steal Credit Card Data From Shoppers

Next Post

Android 17 Enhances Wi-Fi Privacy, Blocking Tracking

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Ethereum Blockchain Used to Steal Credit Card Data From Shoppers
August 31, 2026
Critical Vulnerability in npm Package ‘netmask’ Exposes Credentials
August 31, 2026
Microsoft Defender Bug Triggers False “Antivirus Off” Alerts
August 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us