The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at Socket have identified 18 Google Chrome extensions and one Microsoft Edge extension that can steal wallet secrets and drain cryptocurrency.
- The attacker either bought legitimate extensions from their owners or published clean ones, then later pushed malicious updates that users received automatically through Chrome's default update settings.
- The extensions appear to work normally while secretly connecting to attacker-controlled servers, stealing data, and running modules that can drain crypto wallets, harvest seed phrases and credentials, and hijack social media accounts.
- One extension alone has about 80,000 installs, and the campaign, tracked as Superior, appears to have been active since February 2024, though its operators remain unknown.
What to watch next
- Whether Google and Microsoft remove the flagged extensions from their web stores and revoke them from users' browsers
- Further research into the threat actor behind the Superior campaign and its command-and-control infrastructure
- Any signs the actor acquires additional legitimate extensions to push malicious auto-updates
Coverage1
1 report
English national1
All filed from India
Named India · Chrome Web Store · Enable Right Click & Copy — Smart Unlock + OCR · Google Chrome · Microsoft Edge · QuickLens - Search Screen with Google Lens · Annex Security · DomainTools Investigations · Karlo Zanki · monxresearch-sec · Socket · Superior
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
