Superior Campaign Delivers Malicious Chrome and Edge Extensions
Score: 8/10

Superior Campaign Delivers Malicious Chrome and Edge Extensions

The Superior threat actor uses 19 malicious Chrome and Edge extensions to deliver wallet drainers and credential-stealing payloads through a modular JavaScript framework.

Executive Summary

Socket researchers have identified a large-scale campaign, dubbed "Superior," involving 18 Chrome extensions and one Edge extension that deliver an extendable malware framework. The threat actor employs two primary methods for distribution: creating new utility extensions (e.g., SEO checkers, crypto monitors) and acquiring legitimate, established extensions to weaponize them via auto-updates. One acquired extension, "Enable Right Click & Copy," had a potential impact surface of 80,000 users.

The malware establishes a persistent WebSocket communication channel with a C2 server, strips Content Security Policy (CSP) headers, and uses JavaScript injection to execute modular payloads. These modules are primarily designed for cryptocurrency theft, including hardware wallet phishing (Trezor/Ledger), multi-chain wallet draining, and universal credential grabbing. The campaign dates back to February 2024 and shows high operational maturity, including C2 rotation and distinct exfiltration channels.

This activity represents a significant risk to individuals and organizations due to the bypass of traditional security headers and the exploitation of the trusted extension update ecosystem. While Google has removed the identified Chrome extensions, Microsoft Edge extensions were observed active as of August 2026, highlighting the need for immediate auditing of browser add-ons.

Key Details

Threat Name

Superior Campaign

Affects

—

Adversary

Superior

Malware/Tools

Superior, ClickFix, superior-trezor, superior-ledger, superior-grabber, superior-history

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance7
Clarity & Structure10
Technical Depth8

Sources