Security researchers at Socket found 19 browser extensions — 18 for Chrome and one for Edge — quietly rigged to drain cryptocurrency wallets and harvest login credentials from people who installed them expecting screen readers, ad-spy tools, or crypto price trackers. Google has since pulled the Chrome versions from its store, though the campaign traces back to February 2024 and stayed active for roughly a year and a half before anyone caught it.
Five of the 19 were not built by the attackers at all. They were legitimate extensions with real user bases, purchased from their original developers and then quietly rewritten to include theft code in a later update — a route around Chrome’s review process that lets a proven, trusted listing carry malware straight to an existing install base rather than needing to attract new users from zero.
Nineteen extensions built on an acquisition playbook
Socket calls the operation “Superior,” and its defining trait is patience rather than volume. Rather than publishing 19 obviously malicious tools and hoping people installed them, the group behind it bought five working extensions — including a right-click enabler called “Enable Right Click & Copy” and two Google Lens screen-search tools — and pushed updates that layered in malicious code on top of features that kept functioning normally. The other 14, built from scratch, posed as SEO trackers, ad-library spy tools, and crypto price and wallet-monitoring apps with names like DeFi Pulse Tracker and Multi-Chain Explorer.
A Socket researcher, Karlo Zanki, described the acquisition tactic directly: “The threat actor successfully acquires legitimate extensions and releases new versions empowered with malicious functionality.” Combined with how Chrome and Edge handle extension updates, that meant an install that passed review months earlier could turn hostile without a person doing anything except leaving it installed, since Zanki noted the update mechanism itself “performs auto-updating” once an extension has an established user base.
What the code actually stole
Once active, the extensions targeted a wide surface: wallets built on EVM chains, Solana, and Tron; account credentials for exchanges including Binance, Coinbase, Kraken, KuCoin, OKX, MEXC, and Bybit; and session data for Trezor and Ledger hardware-wallet interfaces accessed through a browser. Beyond crypto specifically, the code also pulled Facebook and LinkedIn login information and general browsing history, according to AndroidHeadlines‘ report on the discovery.
The mechanics were built to slip past standard browser security checks. Rather than making the kind of network requests that would trip content-security-policy or cross-origin protections, the malicious modules routed stolen data out through ordinary browser navigation — traffic that looks, to most monitoring tools, like a person simply visiting another page rather than an extension quietly phoning home with a wallet balance or a saved password. That distinction is a large part of why the campaign ran for roughly a year and a half before Socket’s researchers caught it; the traffic patterns it generated did not resemble the kind of exfiltration security software is built to flag.
One extension, roughly 80,000 users, and an uneven response
“Enable Right Click & Copy — Smart Unlock + OCR” carried the largest exposure of the 19: about 70,000 Chrome installs and 10,000 on Edge, close to 80,000 combined, at the point the weaponized update went out. Socket’s report notes that Google had already removed the Chrome version by the time the research published, but the Edge listing was still live and functioning as malware — and had received a fresh update to its command-and-control infrastructure on August 14, weeks after the Chrome takedown.
That split response, one storefront acting and the other lagging, is the detail that matters for anyone who installed the Edge version specifically. A removal on one platform says nothing about the same extension’s status on another, and Socket’s own account shows Microsoft’s store carrying an actively updated malicious listing well after its Chrome twin had already been pulled. Socket said it reported the Edge listing directly to Microsoft’s own store team rather than waiting for the company to catch it independently, the same kind of direct notification Google appears to have already acted on for the Chrome side.
Cleaning up after installing one of the 19
Google’s Chrome Web Store policy bars exactly this category of behavior outright, prohibiting “spyware, malicious scripts, and phishing scams” from any listed extension — rules the Superior campaign’s later updates violated the moment the malicious code shipped, even though the original, purchased versions had passed review cleanly. AndroidHeadlines’ guidance for anyone who had one of the 19 installed is blunt: assume passwords were compromised and change them across every account tied to that browser profile, starting with a Google Account through its security checkup tool.
For crypto holdings specifically, the exposure does not stop at a password reset. Wallet seed phrases and exchange sessions accessed through a compromised extension may already have been used to move funds by the time anyone notices, which is why the FBI’s Internet Crime Complaint Center urges victims to file a report even when no loss has occurred yet, providing transaction hashes and wallet addresses while warning against paid “recovery services” that promise to reverse transfers cryptocurrency’s design makes irreversible by default.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Early electric-car owners are hitting battery and screen failures no one warned them about
- A magnitude 5.3 quake struck off the Oregon coast this week
- Amazon’s Prime refunds are rising to $200 as millions more customers become eligible
- A handful of car engines are so tough mechanics say they almost never wear out