80,000 Chrome Users Exposed to Superior Malware Framework
Cybercriminals have been using trusted Chrome and Edge extensions to steal crypto wallet keys and session tokens from up to 80,000 users since at least February 2024. Security firm Socket Inc. found that 19 poisoned extensions had been delivering a shared malware framework called 'Superior' through the normal auto-update channel.
The attackers built or bought legitimate-looking utilities that worked as advertised, but once installed, they activated Superior's 16-module framework. This hijacked crypto site buttons, stole session tokens from popular exchanges, and even scraped browsing history and harvested credentials from Facebook and LinkedIn login forms.
The campaign was able to evade Chrome's security architecture, specifically Google's Manifest V3, which replaced powerful network-interception APIs with more limited declarative rules. The attackers abused Chrome's declarative NetRequest API to strip page-level security defenses and inject malicious JavaScript into every site visited.
Google and Microsoft pulled the 19 Superior extensions following Socket's disclosure, but users need to manually remove them from their browser and take steps to secure their accounts. For affected users, this means checking against Socket Inc.'s published list of flagged add-ons and removing any matches immediately.