Malicious Chrome and Edge Extensions Hijack Crypto Wallets and Steal Login Credentials
Brief
Researchers identified 18 malicious Google Chrome extensions and one Microsoft Edge extension that share similar code, infrastructure, and operational techniques.
Socket is tracking the activity as the Superior campaign, which appears connected to malware activity first reported by DomainTools in February 2024 and later analyzed by Secure Annex.
The campaign abuses trust in legitimate-looking browser tools. The affected extensions advertised features such as SEO statistics , crypto-price monitoring, screen-search tools, ad spying, and copy-unlocking utilities.
Their first published versions were clean and performed their claimed functions. After building a user base, attackers released updates that silently added malicious code.
Socket said 14 extensions were created by the threat actors, while five were reportedly acquired from legitimate developers.
