Executive Summary
Socket researchers have identified a large-scale campaign, dubbed "Superior," involving 18 Chrome extensions and one Edge extension that deliver an extendable malware framework. The threat actor employs two primary methods for distribution: creating new utility extensions (e.g., SEO checkers, crypto monitors) and acquiring legitimate, established extensions to weaponize them via auto-updates. One acquired extension, "Enable Right Click & Copy," had a potential impact surface of 80,000 users.
The malware establishes a persistent WebSocket communication channel with a C2 server, strips Content Security Policy (CSP) headers, and uses JavaScript injection to execute modular payloads. These modules are primarily designed for cryptocurrency theft, including hardware wallet phishing (Trezor/Ledger), multi-chain wallet draining, and universal credential grabbing. The campaign dates back to February 2024 and shows high operational maturity, including C2 rotation and distinct exfiltration channels.
This activity represents a significant risk to individuals and organizations due to the bypass of traditional security headers and the exploitation of the trusted extension update ecosystem. While Google has removed the identified Chrome extensions, Microsoft Edge extensions were observed active as of August 2026, highlighting the need for immediate auditing of browser add-ons.
