Browser extension ring hides wallet stealers in plain sight

Socket found 19 Chrome and Edge extensions quietly stealing crypto wallet secrets in the Superior campaign.

CSBadmin
2 Min Read

Eighteen Chrome extensions and one Edge add-on have been caught stealing crypto wallet secrets. Socket researcher Karlo Zanki traced the cluster to a campaign that appears to have run since February 2024, pointing to shared code and infrastructure across the group. Socket calls the operation Superior.

The playbook is simple: the threat actor either acquires legitimate extensions with real functionality or pushes a clean first version, then swaps in a malicious update once downloads accumulate. Of the 19 identified, 14 were created by the operator and five were purchased from previous owners. Infected tools include Enable Right Click and Copy with OCR, RapidLens, QuickLens, Password Protect PDF, Allow Copy for Edge, PixelCheck, Creative Library, MirrorSphere SEO Stats, Site Signal, SEO Pulse Pro, a Private Crypto News Reader, and Blockfolio address monitor, among others.

Zanki says the extensions share code and infrastructure, with evidence of the same campaign fingerprints across the group. Wallet-secret theft typically works by injecting scripts that harvest recovery phrases and private keys as users type them, or by rewriting clipboard content to swap in attacker-controlled addresses during transactions.

Users should audit their extension lists now: remove anything they do not actively use, check permission requests against functionality, and treat clipboard-managing or page-reading extensions from unknown publishers with suspicion. Extension store review remains a weak gate, so organizations should consider browser policies that restrict installs to an approved allowlist for high-value accounts.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.