Superior malicious extension installation campaign
Campaign
Summary
Hide ▲
Show ▼
The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrome Web Store users. The operation has been active since February 2024 and reached at least 19 extensions across Google Chrome and Microsoft Edge, including one with an 80,000-user install base.
Related Happenings
BlueMoon exploit kit deployment across espionage clusters
Malware Activity
H score34
First: 09.09.2026 19:34
Last: 09.09.2026 19:34
Sources 1
About this happening:
BlueMoon is a shared exploit kit used by multiple cyber-espionage groups to chain Google Chrome and Microsoft Windows flaws into code execution, sandbox esca...
BlueMoon exploit kit deployment across espionage clusters
Malware ActivityAbout this happening: BlueMoon is a shared exploit kit used by multiple cyber-espionage groups to chain Google Chrome and Microsoft Windows flaws into code execution, sandbox esca...
Malicious Chrome and Edge browser-extension campaign
Campaign
H score16
First: 30.08.2026 17:17
Last: 30.08.2026 17:17
Sources 1
How related:
The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024.
About this happening:
A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Malicious Chrome and Edge browser-extension campaign
CampaignHow related: The operation was uncovered by application security company Socket, and the investigation indicates that it may have been active since early 2024.
About this happening: A malicious browser-extension campaign turned legitimate Google Chrome and Microsoft Edge add-ons into malware delivery vehicles, putting users at risk of crypto the...
Silent Swap browser-extension clipboard clipper
Malware Activity
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension clipboard clipper
Malware ActivityAbout this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Timeline
-
28.08.2026 18:27 3 articles · 13d ago
Superior-linked Chrome and Edge extensions steal wallet secrets and drain cryptocurrency
Campaign Scope UpdateSuperior-linked browser extensions abused legitimate-looking add-ons for wallet secret theft and cryptocurrency draining. The cluster spans 19 Google Chrome and Microsoft Edge extensions, including Enable Right Click & Copy — Smart Unlock + OCR and QuickLens - Search Screen with Google Lens, and the malicious code can connect to malicious servers, send user data, receive commands, execute arbitrary code, strip Content Security Policy headers, and keep a persistent WebSocket connection. The activity may have been active since February 2024, and the most exposed extension had an 80,000-user install base.
Show sources
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — thehackernews.com — 28.08.2026 18:27
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — thehackernews.com — 28.08.2026 18:27
- Chrome Web Store extensions caught stealing crypto, browser data — www.bleepingcomputer.com — 30.08.2026 17:17