Advisory
Published 2026-08-27
Verified 2026-09-19

Chrome and Edge extensions delivering wallet-drainer malware (Superior)

Socket Threat Research (published 27 August 2026) identified 18 Chrome Web Store extensions and one Microsoft Edge add-on that deliver an extensible malware framework Socket tracks as Superior. Five of the extensions had been acquired from original creators and later pushed malicious updates to existing users; one right-click utility had around 70,000 Chrome users (and about 10,000 on Edge) when malicious functionality appeared. Modules establish encrypted WebSocket C2, strip Content Security Policy headers, and inject payloads that drain crypto wallets, steal credentials and browser history, harvest social accounts, and show ClickFix-style fake update prompts. Google removed the Chrome listings; Socket reported the Edge variant was still live when it published (Edge C2 rotated on 14 August 2026). Users who installed any listed extension should treat credentials as compromised and move crypto to a fresh wallet. Primary: Socket. Secondary: BleepingComputer 30 August.

Product
Google Chrome / Microsoft Edge browser extensions
Versions
19 extension IDs listed in Socket report (Chrome removed; Edge status as of Socket publish)
Exploited in Australia?
unknown
Patch to
Remove listed extensions; rotate credentials; move crypto to a new wallet

Primary: Socket Threat Research ยท Vendor: BleepingComputer (30 Aug; secondary)

tech identity cloud