
Crypto-Theft via Trusted-Looking Extensions: 19 Chrome/Edge Add-Ins Harbor Hidden Malware
Security researchers uncovered 19 Chrome/Edge extensions that mask legitimate functionality while stealing wallet data and draining crypto. The campaign, tracked as Superior by Socket, updates compromised extensions with malicious code after initial benign versions, establishing C2 channels via WebSocket, rotating endpoints, and per‑victim exfiltration. The extensions strip CSP headers to inject 16 malicious modules—ranging from seed-phrase harvesters to credential grabbers—enabling broad data theft. One lead extension, 'Enable Right Click & Copy — Smart Unlock + OCR,' has about 80,000 installs. The attackers reportedly acquired some legitimate extensions or bought them; the operation has been ongoing since February 2024, with broader scope than previously believed. Attribution remains unknown.