At a Glance
| Malware family | “Superior” campaign (crypto wallet drainer / infostealer) |
| Threat actor | Unnamed; suspected link to a campaign tracked since February 2024 |
| Targets / victims | Crypto users; one extension exposed up to 80,000 Chrome and Edge users |
| Delivery vector | 18 Chrome extensions and 1 Edge extension in official stores |
| Key capabilities | Wallet draining, seed-phrase phishing, session theft, credential grabbing |
| Source | Socket Threat Research |
TL;DR
Socket found 19 malicious browser extensions that steal cryptocurrency. The extensions ship clean first, then push a malicious update once they gain trust. Their main goal is wallet secret stealing and crypto draining.
Delivery: Clean First, Malicious Later
The campaign hides in plain sight. Every extension launches with the features it advertises and no malware. Once a base of trust forms, the operators publish an update that turns the tool hostile.
Socket counted 14 extensions built by the threat actor and 5 bought from real developers. They pose as SEO checkers, crypto price monitors, screen search tools, and ad spying utilities. Auto-update settings then spread the poisoned version to existing users.
One extension, “Enable Right Click & Copy – Smart Unlock + OCR,” stands out. It had about 70,000 Chrome users when the malicious code arrived. With its Edge twin, the malicious browser extensions in this pair reach a potential 80,000 people.
Infection Chain
These malicious browser extensions abuse Chrome’s own design. A background service worker talks to a command server and stores downloaded code modules. A content script then injects that code into the pages you visit.
First, the malware strips security headers. It registers a browser rule that removes Content-Security-Policy headers from every site. Socket notes this “is necessary to enable the injection technique” that runs the attacker’s JavaScript.
Next, content scripts create hidden page elements and attach the malicious code as event handlers. The code fires, runs in the page’s main world, and the hidden element is removed to avoid leaving evidence.
Command Server and Data Theft
The latest samples keep a persistent WebSocket connection with a five-minute heartbeat. All errors are silently swallowed. The framework can rotate its command server on instruction, which helps split victims and dodge detection. Downloaded modules are encrypted with AES-GCM in local storage.
The payloads focus on money. A multi-chain drainer hijacks real “Connect Wallet” and “Swap” buttons to authorize theft. Another module serves fake Ledger and Trezor wizards that capture recovery phrases. Others harvest sessions from exchanges like Coinbase, Binance, and Kraken, grab credentials from every form field, and steal browsing history. A ClickFix lure even shows a fake browser update that tricks victims into pasting a command.
Attribution
Socket tracks this activity as the “Superior” campaign. Attribution to a named actor is not confirmed. However, Socket links it with suspected confidence to a campaign first reported by DomainTools in February 2024. Shared code patterns, .top command domains, and near-identical domain names support that connection.
Defense and Detection Guidance
Audit installed extensions and remove anything you do not actively use. Treat broad permissions, such as access to all sites, with suspicion. Keep crypto activity on a separate browser profile or device.
Hardware wallet users should never enter a seed phrase into a browser page. At the time of writing, Google removed the Chrome version, but the Edge extension stayed active and switched to a new command domain on August 14, 2026. Watch for extensions that suddenly request new permissions after an update.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!