# Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal Browser/Exchange Data

> Socket's threat research team identified 19 malicious browser extensions (18 Chrome, 1 Edge) tied to a framework it tracks as 'Superior', active since approximately February 2024. The framework hijacks wallet-connect/swap buttons to drain EVM, Solana, and Tron wallets, phishes Ledger/Trezor seed phrases, steals sessions from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask, harvests Facebook/LinkedIn credentials and browser history, and deploys ClickFix-style fake update lures, all coordinated over encrypted WebSocket C2 channels.

- **Published:** 2026-08-30T00:00:00Z
- **Last reviewed:** 2026-08-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2235
- **ID:** TL-2026-2235
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Socket security researcher Karlo Zanki published findings on August 27, 2026 detailing a coordinated malware framework distributed through 19 browser extensions on the Chrome Web Store and Microsoft Edge Add-ons store, tracked under the name 'Superior'. Fourteen of the extensions were built from scratch by the threat actor under innocuous branding (crypto price trackers, SEO/traffic checkers, ad-library spy tools, screenshot/OCR utilities), while five were legitimate, previously benign extensions with real install bases that the actor purchased from their original developers and later updated with malicious code — most notably 'Enable Right Click & Copy — Smart Unlock + OCR', which had accumulated roughly 70,000 Chrome installs and 10,000 Edge installs before weaponization.

Once activated, the malicious code opens a persistent WebSocket connection to actor-controlled infrastructure and pulls down JavaScript payload modules on demand, keeping the bulk of the malicious logic off the extension package itself to evade Chrome Web Store review. Deployed modules include a multi-chain wallet drainer that detects EVM-compatible, Solana, and Tron wallet activity and silently rewrites the destination of legitimate 'Connect Wallet' and 'Swap' button transactions; a hardware-wallet phishing module that renders fake Ledger and Trezor firmware-update or recovery pages to capture seed phrases; a session-theft module that harvests authentication cookies and account data from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask; a universal form grabber; a Facebook/LinkedIn credential and session harvester; a browser-history exfiltration module; and a ClickFix-style lure that injects a fake browser-update modal instructing victims to paste and run attacker-supplied commands. Several modules strip Content-Security-Policy protections from visited pages to make the injected scripts function on sites that would otherwise block them.

At time of Socket's disclosure and BleepingComputer's follow-up coverage (August 30, 2026), Google had removed the identified extensions from the Chrome Web Store, but the Microsoft Edge Add-ons versions — including 'Allow Copy - Select & Enable Right Click' — remained live and installable. The reliance on Chrome's default silent auto-update mechanism to push the malicious versions to an already-large installed base is the campaign's core distribution technique, and the acquisition of legitimate extensions from their original developers is a supply-chain compromise pattern Socket has documented in related campaigns.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1176 Software Extensions
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1056 Input Capture
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1185 Browser Session Hijacking
- T1005 Data from Local System
- T1217 Browser Information Discovery
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1090 Proxy

## Sources

- [Chrome Web Store extensions caught stealing crypto, browser data](https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/)
- [19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads](https://socket.dev/blog/chrome-edge-extension-wallet-drainer)
- [19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code](https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html)
- [Chrome Extensions Caught Stealing Crypto Wallets](https://u.today/chrome-extensions-caught-stealing-crypto-wallets)
- [19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge](https://thecurrencyanalytics.com/crypto-exchanges/19-malicious-browser-extensions-hit-80000-crypto-users-across-chrome-and-edge-288344)
- [Enable Right Click & Copy — Smart Unlock + OCR (Chrome Web Store listing)](https://chromewebstore.google.com/detail/enable-right-click-copy-%E2%80%94/pkoccklolohdacbfooifnpebakpbeipc)
- [Activate Right Click & Copy — chrome-stats.com extension profile](https://chrome-stats.com/d/pkoccklolohdacbfooifnpebakpbeipc)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2235
