19 Chrome and Edge Extensions Caught Draining Crypto Wallets — What You Need to Know
A two-year-old supply chain campaign just got a lot bigger. Security researchers at Socket have uncovered 19 browser extensions — 18 for Chrome and one for Edge — quietly loaded with code that steals crypto wallet secrets, harvests login credentials, and gives attackers a persistent backdoor into victims’ browsers.

How the Attack Works
This isn’t your typical “download a fake app” scam. The threat actor behind this campaign, tracked by Socket under the name Superior, uses a patient, two-stage approach:
- Acquire trust first. The attacker either buys an existing, legitimate extension that already has a real user base, or publishes a brand-new extension that works exactly as advertised — no malware, nothing suspicious, just a genuinely useful tool.
- Flip it later. Once the extension has racked up downloads and earned a reputation, the attacker pushes an “update” that quietly adds the malicious functionality.
That timing is what makes this campaign so effective. Chrome and Edge auto-update extensions by default, so every existing user gets the malicious version without doing anything — no new install, no obvious warning sign, no click required. Researchers believe this activity has been running since February 2024, with some pieces first documented publicly back in May 2025.
The most-installed extension in the cluster, a right-click/copy-enabler tool, alone accounts for roughly 80,000 installs across both browsers.
What the Malicious Code Actually Does
Once active, the extensions strip Content Security Policy protections from every page a victim visits and inject malicious scripts. Researchers identified 16 distinct malicious modules, capable of:
- Draining funds from multi-chain crypto wallets
- Harvesting seed phrases from hardware wallets
- Stealing crypto exchange and wallet account credentials
- Grabbing usernames and passwords from any web form
- Hijacking Facebook and LinkedIn accounts
- Stealing browser history
- Running a “ClickFix”-style scam that tricks users into pasting a malicious command onto their own machine, disguised as a browser update
The extensions also maintain a live connection to attacker-controlled servers, which can reroute victims to different command-and-control infrastructure on the fly — a technique that helps the operation spread risk across victims and stay ahead of takedowns.
The Full List of Affected Extensions
Purchased from previous owners:
| Extension ID | Name |
|---|---|
koccklolohdacbfooifnpebakpbeipc | Enable Right Click & Copy — Smart Unlock + OCR |
fegckejpfnlmfgkfjpinlbgmeeijjkel | RapidLens – Google Lens for Screen Search & Images |
kdenlnncndfnhkognokgfpabgkgehodd | QuickLens – Search Screen with Google Lens |
jamminefolhgepgihbmcjjhgldbfcikp | Password Protect PDF |
inmkjedjdhgpknjogbjomhnbgdccckkg | Allow Copy – Select & Enable Right Click (Edge) |
Created and published directly by the threat actor:
| Extension ID | Name |
|---|---|
fcgdejjichpgfaaafflplhfijcnieopb | PixelCheck |
cfpnjdbpojpcongfaefcamjbaolpelcd | Creative Library – Ad Spy Tool |
aapdalkmclfaahehnmicbglkohkldhne | Website Traffic Checker: MirrorSphere SEO Stats |
dkdadldmiefjldmegbjbnhhfddnkhlhm | Site Signal – Website Traffic & SEO Checker |
fjmlhlkccegopebcllcmafahkmeejpph | SEO Pulse Pro – Website Traffic & SEO Analyzer |
iekoapohahgmogbagegmcgplbkikcgke | Private Crypto News Reader |
ahpnnnjbnfbhoikhohglpohnoocjcoco | Blockfolio: Address Monitor |
oeacadlaclegkkkdehjmiifnjhcekclj | Crypto Rates & Fiat Converter |
jmlgannjlbliikgcaieomgmcnfplglea | Crypto Alerter: Price Alarms & Volatility Warnings |
lhmcajhgadanidbopgaoobjlldegjmke | DeFi Pulse Tracker |
gfackggoapepdmnjnkblogdcjpgcjiak | Crypto Price Badge: Quick Glance |
hfijkbdkpidafdbeebnnkhfccildbcle | Multi-Chain Explorer |
cngchfbfgejllcbhmeadjhiebebiome | LedgerLook: Wallet Checker |
aodkjdeghbjiaienipfjkbpcikkacbcp | Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray |
What to Do About It
- Check for these extension IDs across your organization and any personal browsers — the ID is the reliable identifier, since names and icons can be reused or changed.
- Uninstall immediately if any match is found, and treat affected devices as compromised: rotate crypto wallet credentials, exchange logins, and any passwords that may have been typed while the extension was active.
- Don’t rely on “I checked it once.” Auto-updating extensions can turn malicious long after installation, so a one-time vetting pass isn’t enough.
- Consider extension allowlisting. Chrome Enterprise and Edge for Business both support policies that restrict which extensions can be installed at all, which is the most durable defense against this exact attack pattern.
Source: Socket security research, as reported by The Hacker News, August 28, 2026.
