VMTech
Discuss a project

Nineteen Chrome and Edge Extensions Linked to Wallet Theft

Nineteen Chrome and Edge Extensions Linked to Wallet Theft

Security researchers have identified 18 Google Chrome extensions and one Microsoft Edge extension containing code for stealing wallet secrets and draining cryptocurrency accounts. Socket researcher Karlo Zanki said the cluster, tracked as Superior, includes extensions published over the past six months and may have been active since February 2024.

The campaign combines extensions created by the operator with products acquired from previous owners. Fourteen of the 19 identified extensions were created by the threat actor, while five were purchased. The most widely installed example, Enable Right Click & Copy — Smart Unlock + OCR, has a combined install base of 80,000 users across Chrome and Edge.

Trusted extensions can change after installation

Socket described a simple but consequential operating model: an actor either purchases a legitimate extension with working features or releases an initially clean product. After it gains downloads, a later update introduces malicious behaviour. Chrome’s default extension update settings can then distribute that new version automatically to existing users.

QuickLens - Search Screen with Google Lens had already been flagged by Annex Security and monxresearch-sec for pushing malware to downstream users, injecting arbitrary code and collecting sensitive data. Socket’s findings indicate that the activity is broader than that individual extension. DomainTools Investigations also documented related activity in May 2025, including fake sites posing as productivity, advertising, media, VPN, cryptocurrency and banking tools.

The operational risk aligns with concerns raised in Edge browser password exposure risks about passwords retained in Edge memory, because browser-resident data and extension permissions can create complementary paths to sensitive accounts.

Command servers and modular theft functions

The affected extensions appear to retain their advertised functionality while also contacting malicious infrastructure. They can send user data, receive commands and execute arbitrary code. Each supports command-and-control communication and a persistent WebSocket connection.

Zanki said the loading framework can rotate its command-and-control endpoint on instructions from an initial server, a capability observed in the wild. It can also receive a data-exfiltration endpoint dynamically, enabling separate channels for individual victims and making infrastructure-based detection more difficult.

In QuickLens, malicious code removed Content Security Policy headers from every page and enabled JavaScript modules to be injected into targeted sites through content scripts. Researchers identified 16 modules covering multi-chain wallet draining, hardware-wallet seed-phrase harvesting, cryptocurrency exchange and wallet account collection, universal credential or form grabbing, Facebook and LinkedIn account theft, browser-history theft and a ClickFix-style lure.

The ClickFix component presents a fake browser update and uses operating-system-specific instructions to persuade users to copy and run a malicious command. The operator has not been identified, but Socket said the campaign’s duration suggests a capable threat actor.

Business implication

Businesses should maintain an inventory of browser extensions, restrict installations to justified and reviewed tools, and reassess extensions after ownership or version changes. The key exposure is not only an obviously malicious download: a previously trusted extension can receive a harmful update after it is already deployed.

#cybersecurity#browsersecurity#cryptowallets#supplychain
Open analytics
On the site 0 views
min read 4 28.08.2026
Instagram

Nineteen Chrome and Edge Extensions Linked to Wallet Theft

Open the post on Instagram ↗