Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Socket, a vendor specializing in software supply-chain security, has identified 19 malicious browser extensions distributed through the Chrome Web Store and the Edge Add-ons Store. The campaign, dubbed 'Superior' by researchers, infected a combined install base of nearly 80,000 users through an insidious mechanism: the acquisition of legitimate extensions and their conversion via automatic update into data-exfiltration platforms. Technical evidence collected by Socket indicates continuous activity since February 2024, with operations spanning over two years.
- 19 extensions identified: 18 for Google Chrome, 1 for Microsoft Edge; 5 acquired from legitimate developers, 14 created directly by the threat actor
- The modular malware framework comprises 16 specialized components for stealing crypto assets, credentials, exchange sessions, and social data
- The most impactful extension, 'Enable Right Click & Copy — Smart Unlock + OCR', had an install base of roughly 70,000 Chrome users and 10,000 Edge users
- The automatic extension-update mechanism turns inherited trust into an attack vector: users receive no notifications when ownership changes or code is modified
Inherited Trust as a Weapon: Acquisition and Silent Weaponization
The threat actor built its infrastructure on a principle of offensive economy. Fourteen extensions were created from scratch; five were acquired from legitimate developers with an already-consolidated user base. This duality is functional: acquired extensions inherit positive reviews, search rankings, and routine installation behaviors that the end user does not interrupt.
The conversion occurs through the automatic update mechanism built into Chrome and Edge. When the threat actor publishes a new version of an acquired extension, the browser installs it without explicit interaction. The malicious code activates in the extension's privileged context, with access to open tabs, cookies, local storage, and browser APIs. According to Socket researcher Karlo Zanki: "The biggest risk for end-users is the operational technique in which the threat actor successfully acquires legitimate extensions and releases new versions empowered with malicious functionality."
Zanki adds: "That approach, combined with Chrome's default extension update settings, performs auto-updating to the latest version of extension, providing the threat actor with a powerful vector to maximize the impact and reach of the extension acquisition." The result is that a user who installed a legitimate utility to enable right-click or manage passwords finds themselves with an active exfiltration agent in their browser profile.
16-Module Framework: Modular Architecture and WebSocket C2 with Rotation
The payload is not a monolithic infostealer but a loader framework designed to be "highly extensible," as Socket documents. Sixteen distinct modules operate in coordination, each with a specific target. Identified modules include: draining of EVM, Solana, and Tron wallets; seed-phishing with fake Ledger and Trezor interfaces; theft of active sessions on Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask; credential logging and form harvesting; harvesting of Facebook and LinkedIn accounts; and a ClickFix module that injects fake browser updates with OS-specific instructions to execute malicious commands copied and pasted by the user.
Communication with the command-and-control server occurs via encrypted WebSocket. A technically relevant element is the rotation of C2 endpoints: the framework receives instructions from the initial server to move to a new node, distributing victims across dedicated infrastructure. Zanki notes: "Worth noting is that the loading framework supports rotation of the C2 endpoint based on instructions received from the initial C2 server and this behavior has been observed in the wild." He adds: "That functionality enables threat actors to distribute victims to different groups and dedicated C2 infrastructure and to reduce the detection risk."
The framework also strips Content Security Policy (CSP) headers from every visited page, neutralizing one of the modern web's standard defenses. Malicious script injection occurs via hidden HTML elements, with content scripts operating in the context of target pages. The combination of C2 rotation, per-victim exfiltration channels, and CSP removal makes network-based detection extremely difficult: the apparent traffic is a legitimate WebSocket connection to a domain that changes, and exfiltration blends with the normal HTTP flow of the compromised page.
"The biggest risk for end-users is the operational technique in which the threat actor successfully acquires legitimate extensions and releases new versions empowered with malicious functionality" — Karlo Zanki, Socket security researcher
The Structural Flaw in Extension Stores: Unreviewed Updates and Absent Transparency
The 'Superior' case exposes a governance deficit in extension marketplaces. The Chrome Web Store and Edge Add-ons Store review procedures are designed for the moment of initial publication, not for every subsequent update. A transfer of ownership between developers generates no notifications to installed users; the change of publisher account, even when it entails transfer of access to thousands of users, passes in silence.
Google removed the 18 Chrome extensions identified by Socket at the time of the report's publication. The Edge version, unique in the sample, remained available in the Edge Add-ons Store as of the same date. This asynchrony between the two official stores — both controlled by Big Tech with considerable security resources — indicates the problem is not analytical capacity but procedural design. Corporate extensions, often managed with permissive policies allowing installation from official stores without specific whitelists, amplify the risk in enterprise environments.
This is not the first time this vector has been exploited. Socket documents that DomainTools Investigations had observed correlated aspects of the campaign as early as May 2025; Annex Security and monxresearch-sec had flagged the QuickLens extension in early 2026. The campaign operated for over two years with recognizable techniques, without the stores' automated controls interrupting the chain of malicious updates.
What to Do Now
Socket has published the complete list of extension IDs and associated C2 domains. Users who installed productivity utilities, password managers, or accessibility tools in recent months should verify the presence of the IDs indicated in the report. Removing a compromised extension stops exfiltration but does not mitigate data already collected.
Organizations managing browser fleets via Microsoft Endpoint Manager or Google Admin Console can block automatic installation of updates for non-whitelisted extensions, or revoke specific IDs from the corporate catalog. Effective control requires a shift from permissive policies to allow-listing models, with periodic review of installed extensions even when they originate from verified stores.
For individual users, manual verification of active extensions in their browser profile is the immediate step. The presence of utilities installed months or years ago, even with positive reviews at the time of installation, does not guarantee current security: the code executing today is that of the latest update, not the original version.
The incident does not require specific actions from Google or Microsoft beyond the removal already performed or underway; the dossier does not document software patches, browser security updates, or procedural changes announced by the vendors.
Why This Changes the Perception of Browser Risk
The 'Superior' campaign inverts the traditional user threat model. It is no longer necessary to convince the victim to install dubious software: it suffices to acquire what they already have installed. The legitimate extension becomes a trojan without the concept of "suspicious installation" making sense anymore. The defense perimeter shifts from the endpoint to the marketplace, from the moment of installation to every single subsequent update.
The browser security sector must confront an incentive-design problem. Stores profit from the quantity of extensions and the fluidity of updates; continuous verification is a cost. As long as ownership changes remain opaque and updates go unreviewed, the 'Superior' vector remains reproducible by any threat actor with sufficient capital to acquire established extensions. The trust users grant to official platforms is, in this case, the entry point.
Sources
- https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/
- https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
- https://www.tradingview.com/news/u_today:461838749094b:0-chrome-extensions-caught-stealing-crypto-wallets/
- https://www.bleepingcomputer.com/
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
- https://deals.bleepingcomputer.com/
- https://www.bleepingcomputer.com/vpn/
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.