Malicious Extensions Infect 80,000 Users, Steal Wallet Secrets, Drain Crypto
Cybersecurity researchers at Socket have discovered a cluster of 19 Chrome and Edge extensions that were published over the last six months and harbored wallet-stealing and cryptocurrency draining capabilities.
The threat actor, tracked under the name Superior by Socket, has been active since February 2024. The modus operandi is relatively straightforward: the attacker either acquires legitimate extensions with proper functionality or pushes a clean version that's devoid of any malware.
Of the identified extensions, 14 were created by the threat actor, while the remaining five were purchased from their previous owners. Some aspects of this campaign were documented by DomainTools Investigations in May 2025, detailing the creation of fake websites and productivity tools to trick users into installing malicious extensions.