Cybersecurity researchers have identified a cluster of 19 browser extensions for Google Chrome and Microsoft Edge that contain wallet secret stealing and cryptocurrency draining capabilities, raising concerns about the security of browser based tools used by thousands of people. According to Socket security researcher Karlo Zanki, the campaign includes 18 Chrome extensions and one Microsoft Edge extension that were published during the last six months. The researcher said the extensions share similarities in code structure and operational methods, with evidence indicating the activity has been ongoing since February 2024. Socket is tracking the campaign under the name Superior. The findings suggest the threat actor follows a strategy of either acquiring legitimate browser extensions with existing functionality or publishing clean extensions without malicious code. After these extensions gain a user base and establish trust, updated versions containing malicious functionality are released through the official browser extension stores, allowing the harmful code to reach users through standard automatic updates.
Researchers found that 14 of the identified extensions were created and published by the threat actor, while five were acquired from previous owners before being updated. The acquired extensions include Enable Right Click & Copy Smart Unlock + OCR, RapidLens Google Lens for Screen Search & Images, QuickLens Search Screen with Google Lens, Password Protect PDF, and Allow Copy Select & Enable Right Click for Microsoft Edge. Among the extensions developed directly by the operator are PixelCheck, Creative Library Ad Spy Tool, Website Traffic Checker MirrorSphere SEO Stats, Site Signal Website Traffic and SEO Checker, SEO Pulse Pro Website Traffic and SEO Analyzer, Private Crypto News Reader, Blockfolio Address Monitor, Crypto Rates and Fiat Converter, Crypto Alerter Price Alarms and Volatility Warnings, DeFi Pulse Tracker, Crypto Price Badge Quick Glance, Multi Chain Explorer, LedgerLook Wallet Checker, and Meta & Facebook Ad Library Spy Save Ads, Finder, Downloader FeedX Ray. Researchers noted that QuickLens had previously been identified by Annex Security and monxresearch sec earlier this year for its ability to deliver malware, inject arbitrary code, and collect sensitive information from users. The latest research from Socket indicates the campaign is broader than initially believed, while earlier investigations by DomainTools in May 2025 also documented similar activity involving fake websites designed to imitate legitimate productivity tools, advertising services, VPN solutions, cryptocurrency utilities, and banking applications in an effort to convince users to install malicious browser extensions.
According to the researchers, the extensions generally continue to perform their advertised functions, making them appear legitimate, while simultaneously communicating with remote command and control servers to receive instructions, send collected data, and execute additional code. The extension considered to have the highest potential impact is Enable Right Click & Copy Smart Unlock + OCR, which reportedly has a combined installation base of around 80,000 users across Chrome and Edge. Each extension can establish persistent WebSocket connections with command and control infrastructure, allowing operators to dynamically change communication endpoints and data exfiltration servers based on instructions received during operation. Researchers explained that this rotating infrastructure helps distribute victims across different servers and reduces the likelihood of detection while enabling customized data collection for individual users. In the case of QuickLens, the malicious code removes Content Security Policy headers from visited websites, making it easier to inject JavaScript modules into targeted pages. Investigators identified 16 separate modules that support multiple capabilities, including draining cryptocurrency wallets across different blockchain networks, harvesting hardware wallet recovery phrases, collecting credentials from cryptocurrency exchanges and wallet services, capturing browser forms and login details, stealing Facebook and LinkedIn account information, collecting browser history, and displaying ClickFix style browser update prompts that encourage users to copy and paste malicious commands based on their operating system.
Researchers said the identity of the operator behind the campaign remains unknown, but the ability to sustain the activity for more than two years suggests a highly capable threat actor with a well established operational process. They emphasized that one of the most significant risks comes from the acquisition of trusted browser extensions that already have an existing user base. Since Chrome and Edge automatically install extension updates by default, users may unknowingly receive malicious versions without taking any action. This approach allows attackers to maximize the reach of compromised extensions while maintaining the appearance of legitimate software. The findings highlight the importance of regularly reviewing installed browser extensions, monitoring unexpected permission requests, and removing extensions that are no longer needed, particularly those that undergo significant ownership or functionality changes after installation.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





