Browser Extension Danger

19 Chrome and Edge Extensions Caught Draining Crypto Wallets — What You Need to Know

A two-year-old supply chain campaign just got a lot bigger. Security researchers at Socket have uncovered 19 browser extensions — 18 for Chrome and one for Edge — quietly loaded with code that steals crypto wallet secrets, harvests login credentials, and gives attackers a persistent backdoor into victims’ browsers.

How the Attack Works

This isn’t your typical “download a fake app” scam. The threat actor behind this campaign, tracked by Socket under the name Superior, uses a patient, two-stage approach:

  1. Acquire trust first. The attacker either buys an existing, legitimate extension that already has a real user base, or publishes a brand-new extension that works exactly as advertised — no malware, nothing suspicious, just a genuinely useful tool.
  2. Flip it later. Once the extension has racked up downloads and earned a reputation, the attacker pushes an “update” that quietly adds the malicious functionality.

That timing is what makes this campaign so effective. Chrome and Edge auto-update extensions by default, so every existing user gets the malicious version without doing anything — no new install, no obvious warning sign, no click required. Researchers believe this activity has been running since February 2024, with some pieces first documented publicly back in May 2025.

The most-installed extension in the cluster, a right-click/copy-enabler tool, alone accounts for roughly 80,000 installs across both browsers.

What the Malicious Code Actually Does

Once active, the extensions strip Content Security Policy protections from every page a victim visits and inject malicious scripts. Researchers identified 16 distinct malicious modules, capable of:

  • Draining funds from multi-chain crypto wallets
  • Harvesting seed phrases from hardware wallets
  • Stealing crypto exchange and wallet account credentials
  • Grabbing usernames and passwords from any web form
  • Hijacking Facebook and LinkedIn accounts
  • Stealing browser history
  • Running a “ClickFix”-style scam that tricks users into pasting a malicious command onto their own machine, disguised as a browser update

The extensions also maintain a live connection to attacker-controlled servers, which can reroute victims to different command-and-control infrastructure on the fly — a technique that helps the operation spread risk across victims and stay ahead of takedowns.

The Full List of Affected Extensions

Purchased from previous owners:

Extension IDName
koccklolohdacbfooifnpebakpbeipcEnable Right Click & Copy — Smart Unlock + OCR
fegckejpfnlmfgkfjpinlbgmeeijjkelRapidLens – Google Lens for Screen Search & Images
kdenlnncndfnhkognokgfpabgkgehoddQuickLens – Search Screen with Google Lens
jamminefolhgepgihbmcjjhgldbfcikpPassword Protect PDF
inmkjedjdhgpknjogbjomhnbgdccckkgAllow Copy – Select & Enable Right Click (Edge)

Created and published directly by the threat actor:

Extension IDName
fcgdejjichpgfaaafflplhfijcnieopbPixelCheck
cfpnjdbpojpcongfaefcamjbaolpelcdCreative Library – Ad Spy Tool
aapdalkmclfaahehnmicbglkohkldhneWebsite Traffic Checker: MirrorSphere SEO Stats
dkdadldmiefjldmegbjbnhhfddnkhlhmSite Signal – Website Traffic & SEO Checker
fjmlhlkccegopebcllcmafahkmeejpphSEO Pulse Pro – Website Traffic & SEO Analyzer
iekoapohahgmogbagegmcgplbkikcgkePrivate Crypto News Reader
ahpnnnjbnfbhoikhohglpohnoocjcocoBlockfolio: Address Monitor
oeacadlaclegkkkdehjmiifnjhcekcljCrypto Rates & Fiat Converter
jmlgannjlbliikgcaieomgmcnfplgleaCrypto Alerter: Price Alarms & Volatility Warnings
lhmcajhgadanidbopgaoobjlldegjmkeDeFi Pulse Tracker
gfackggoapepdmnjnkblogdcjpgcjiakCrypto Price Badge: Quick Glance
hfijkbdkpidafdbeebnnkhfccildbcleMulti-Chain Explorer
cngchfbfgejllcbhmeadjhiebebiomeLedgerLook: Wallet Checker
aodkjdeghbjiaienipfjkbpcikkacbcpMeta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray

What to Do About It

  • Check for these extension IDs across your organization and any personal browsers — the ID is the reliable identifier, since names and icons can be reused or changed.
  • Uninstall immediately if any match is found, and treat affected devices as compromised: rotate crypto wallet credentials, exchange logins, and any passwords that may have been typed while the extension was active.
  • Don’t rely on “I checked it once.” Auto-updating extensions can turn malicious long after installation, so a one-time vetting pass isn’t enough.
  • Consider extension allowlisting. Chrome Enterprise and Edge for Business both support policies that restrict which extensions can be installed at all, which is the most durable defense against this exact attack pattern.

Source: Socket security research, as reported by The Hacker News, August 28, 2026.

Browser Extension Danger
Scroll to top