Cybersecurity researchers have uncovered a group of 19 browser extensions that were designed to steal sensitive information, including cryptocurrency wallet secrets and credentials.

The campaign involves 18 Google Chrome extensions and one Microsoft Edge extension, with researchers warning that the activity may have been running since February 2024.

Security firm Socket has been tracking the campaign under the name “Superior.” Researcher Karlo Zanki said the extensions share similarities in their code and attack techniques, suggesting they are connected to the same operation.

The attackers appear to have used a particularly effective supply-chain strategy. In some cases, they acquired legitimate browser extensions that already had users and positive download numbers. In other cases, they released clean versions of their own extensions first. After the extensions gained users, malicious versions were pushed through updates.

Socket identified 14 extensions created by the attackers and five that were purchased from their original developers. The affected extensions include tools for enabling right-click functionality, Google Lens searches, PDF protection, SEO analysis, cryptocurrency tracking, wallet monitoring and advertising research.

One of the most concerning examples is “Enable Right Click & Copy — Smart Unlock + OCR,” which has a combined installation base of around 80,000 users across Chrome and Edge. Other extensions identified in the campaign include RapidLens, QuickLens, PixelCheck, Creative Library, MirrorSphere SEO Stats, Site Signal, SEO Pulse Pro, Private Crypto News Reader, Blockfolio: Address Monitor, Crypto Rates & Fiat Converter, Crypto Alerter, DeFi Pulse Tracker, Crypto Price Badge, Multi-Chain Explorer, LedgerLook and FeedX-Ray.

READ
TikTok to Pay $400 Million to Settle US Children’s Privacy Case

QuickLens had already been flagged earlier this year by security researchers after it was found capable of pushing malicious code to users, injecting arbitrary JavaScript and collecting sensitive information. Socket’s latest investigation indicates that the activity is much broader than previously known.

The campaign also appears to overlap with activity documented by DomainTools Investigations in May 2025. Researchers previously observed the threat actor operating fake websites that impersonated legitimate productivity tools, media and advertising services, VPNs, cryptocurrency utilities and banking-related applications. These websites were used to convince people to install malicious browser extensions.

The extensions are designed to maintain their legitimate-looking functionality while secretly communicating with attacker-controlled servers. According to researchers, they can send stolen information to those servers, receive commands and execute additional code.

The malicious extensions can also establish persistent WebSocket connections with command-and-control infrastructure. Researchers found that the framework can receive instructions from an initial C2 server and then switch to another endpoint. This allows attackers to distribute victims across different infrastructure and potentially make the campaign harder to detect.

The stolen information can include cryptocurrency wallet data, hardware-wallet seed phrases, exchange and wallet account information, browser credentials, submitted form data and browser history. Researchers also identified modules targeting Facebook and LinkedIn accounts.

Another component uses a ClickFix-style technique. It can display a fake browser update or similar warning and provide operating-system-specific instructions designed to convince users to copy and paste a malicious command onto their computers.

READ
Brazil Sues Discord for $97M Over Child Safety Failures

Researchers also found that the malware can interfere with Content Security Policy protections on websites. In the case of QuickLens, the malicious code removes CSP headers and enables JavaScript modules to be injected into targeted websites through content scripts. Socket identified 16 different modules covering wallet draining, credential theft, account theft and other malicious activities.

The identity of the operators remains unknown, but researchers believe the campaign demonstrates a high level of capability. The biggest concern is the attackers’ use of legitimate extensions as an initial distribution channel.


Buy ExpressVPN with PayPal or Credit Card

Because Chrome normally updates installed extensions automatically, users who originally installed a harmless extension could later receive a malicious version without knowingly installing new software. This makes extension ownership transfers and malicious updates a particularly effective way for attackers to reach existing users.

Advertisement