Malicious Chrome and Edge Extensions Steal Crypto Wallets and Passwords
Key Takeaways A sophisticated malware campaign, dubbed “Superior,” compromised 19 browser extensions across Google Chrome and Microsoft Edge. The attackers acquired legitimate extensions...
Key Takeaways
- A sophisticated malware campaign, dubbed “Superior,” compromised 19 browser extensions across Google Chrome and Microsoft Edge.
- The attackers acquired legitimate extensions and injected malicious code via routine updates, affecting up to 80,000 users.
- The malware primarily targets cryptocurrency wallets, aiming to steal seed phrases, drain funds, and capture session data from exchanges like Coinbase and Binance.
- Beyond crypto, the extensions can steal passwords, browsing history, and social media data through a flexible, modular framework.
- Users are urged to review installed extensions, remove unneeded ones, and change sensitive credentials if they suspect compromise.
A recent analysis has uncovered a widespread malware operation leveraging 19 popular browser extensions to illicitly obtain cryptocurrency wallet information, passwords, and other sensitive user data. The compromised extensions, initially appearing as benign utilities such as search enhancers, price trackers, and copy-unlocking tools, were later updated with stealthy malicious code.
The campaign specifically targeted 18 extensions available for Google Chrome and one for Microsoft Edge. Attackers employed a deceptive strategy: they acquired existing, trusted add-ons with established user bases. Subsequent automatic updates then delivered the harmful functionalities, exploiting the trust users had in the original developers. Two of these compromised extensions alone had a potential reach of 80,000 users.
Researchers at Socket.dev identified this operation, naming it “Superior” based on internal labels found within its JavaScript modules. According to a report from Socket.dev, the primary objective of this campaign is to facilitate wallet theft and drain cryptocurrency. However, the malware is also capable of exfiltrating login credentials, session tokens, and browsing history.
This discovery highlights a critical vulnerability in the browser extension ecosystem: an extension’s initial legitimacy does not guarantee its ongoing safety. The practice of injecting malicious code into otherwise familiar tools through post-publication updates creates a significant risk, mirroring concerns raised in past compromised Chrome extension campaigns.
Details of the Superior Campaign
Socket researchers determined that 14 of the compromised extensions were developed by the threat actors themselves, while five were reportedly purchased from their original, legitimate developers. This strategy of introducing clean initial releases to build user trust, followed by malicious updates, makes it difficult for users to detect when an extension’s ownership has changed and its security posture has been compromised.
One of the most widely used affected extensions was “Enable Right Click & Copy – Smart Unlock + OCR.” While Google has since removed its Chrome version, the corresponding Edge version remained active and continued to deliver malware at the time of the research publication. This highlights a critical point: the removal of an extension from one store does not automatically uninstall it from users’ browsers or prevent a related version from operating on another platform.
The malware operates by establishing an encrypted WebSocket channel to attacker-controlled infrastructure. This channel is used to download and execute various code modules designed for specific malicious tasks. The system is also resilient, capable of switching to alternative command-and-control (C2) servers and using separate destinations for exfiltrated data. This modular and adaptive design allows the attackers to modify the malware’s behavior without requiring a new, visibly distinct extension version.
A key technique employed by the malware involves removing the browser’s Content Security Policy (CSP) header from visited web pages. The CSP is a vital security mechanism that limits the scripts a website can load, thereby preventing cross-site scripting (XSS) attacks. By bypassing this safeguard, the malicious extension can inject arbitrary code into web pages and activate it through hidden elements, a tactic reminiscent of other malicious Chrome security bypasses.
Wallet Drainers and Password Theft
The modules downloaded by the “Superior” malware are designed to target several high-value data types. A dedicated wallet drainer module identifies Ethereum Virtual Machine (EVM), Solana, and Tron wallets. It then maliciously replaces legitimate “Connect Wallet” or “Swap” button functionalities with requests controlled by the attackers. Another module employs convincing fake recovery or update screens to trick users into divulging their seed phrases, which would grant attackers full control over their cryptocurrency wallets.
Beyond direct wallet compromise, other modules focus on extracting data from active exchange and wallet sessions. This includes harvesting cookies, access tokens, profile details, and account balances from popular services such as Coinbase, Binance, Kraken, and MetaMask.
A universal form grabber embedded within the malware records text, email addresses, and password fields across all websites visited by the victim. This broad data collection capability extends the threat beyond cryptocurrency, potentially exposing personal accounts and even corporate login credentials.
The campaign also incorporates social media data theft, comprehensive browsing history collection, and deceptive browser update prompts. These fake prompts can copy an attacker-supplied command to the clipboard and instruct the victim to paste it into their computer, a dangerous tactic for gaining further system access. Such unexpected update instructions should always be treated with extreme suspicion, especially when a website requests command execution, as seen in recent <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/0dead0e4-b369-44d4-8fe9-f71ea76e0d7b/19-Chrome-and-Edge-Extensions-Caught-Stealing-Crypto-Wallets-and-Passwords.pdf?AWSAccessKeyId=ASIA2F3EMEYETJ3FO3CA&Signature=g6ikjeZPD4at5OlXpQT%2BJuajFtI%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCsTiGPi5CFyYGYYuy367pRR8TlskT1u2scm3CAvcEChgIhAJMckSokQcsmuJMQDt7RLh7ZS5%2B5TJJgph0ny55o6P66KvwECJT%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgwKzIIhDs8oPiVsnRkq0ARVvf7HI1iO%2BEBNskA9smBUTpK4Id8DVcRrbpHVEJLl3CKQTvWk4kwCMQtpMKlL%2B5e4OZIHvLy8k8MIFlUy5PR4erhVfyABxd06NV1WX8vJy5t5C3g5fmUauqIEXGRN%2F5KvlxVpLCzxtupsEkkS60TrbCmeQnQfqlceKtKIzgddjUBibmMqvS3QAih9KwjcMJDxyyg9Gw27Qv2RhFPWk69m4COtuRc63rXbu9fiZEjUbyNkWbwDnQ9VubifNwgDHnNVqbFmGwcewIaoODhvwjPoZnoc0B2EMKwLeUWjl1NN4E6mXgylyRQJRG6OJfPiHTbp%2Bm%2BmHoIBYe5FlPiyBFa9FxK67sQy2VVafkrArUAy9lhYRwhql6%2FZOxaJC7s7HJpIKZT7KCB9NrhXmtZM1
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.