19 Chrome and Edge Extensions Deliver Wallet Drainers and Credential-Stealing Malware

Summary
Socket analyzed 19 malicious Chrome and Edge extensions linked to the Superior campaign. Their C2-controlled malware can steal wallet secrets, credentials, session data and browsing history; one Edge extension was still active when reported.
Key points
- Socket identified 18 malicious Chrome extensions and one Edge extension, linking their techniques to a campaign tracked as Superior that dates back to February 2024.
- The extensions establish WebSocket connections to C2 servers, download modular JavaScript payloads and can rotate C2 and exfiltration endpoints.
- They strip Content Security Policy protections and inject downloaded code into visited websites, enabling payload execution in the page context.
- Observed modules target cryptocurrency wallets and exchange accounts, steal recovery phrases, credentials and session data, harvest social-media information, and exfiltrate browsing history.
- The operators publish clean versions before adding malware and have also acquired legitimate extensions; one acquired extension had about 70,000 Chrome users and 10,000 Edge users.
- At the time of Socket’s report, the malicious Chrome extension had been removed from the Chrome Web Store, while its Edge counterpart remained active and had been reported to the Edge extension store.
Article Details
- Attack Vectors
- The threat actor published initially clean extensions and later introduced malicious functionality through updates. Five extensions had been acquired from legitimate authors; 14 were threat actor-created.
- Malicious extension service workers contact C2 servers, receive JavaScript modules, and store them in extension local storage. Observed versions use persistent WebSocket connections, and the framework supports C2 endpoint rotation.
- The extensions remove Content Security Policy headers from visited pages and trigger downloaded JavaScript through event handlers on temporary hidden DOM elements.
- Observed modules hijack wallet connection and swap buttons, present fake hardware-wallet restoration flows to capture recovery phrases, collect authenticated session material, and capture form inputs.
- A fake browser-update lure instructs users to paste and run an attacker-supplied command.
- Defensive Notes
- Review installed browser extensions regularly and remove unnecessary or suspicious ones.
- Exercise caution before installing extensions and continue monitoring trusted extensions, because ownership and behavior can change through updates.
- Socket reported that the malicious Chrome version of Enable Right Click & Copy — Smart Unlock + OCR had been removed from the Chrome Web Store, while its Edge version was still serving malware at the time of writing. Socket reported the Edge finding to its extension store.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | active-enable-right-click[.]top | Listed primary C2 domain. |
| DOMAIN | api[.]active-enable-right-click[.]top | C2 endpoint domain shown in the extension's default configuration code. |
| DOMAIN | api[.]codefilearc[.]net | Listed primary C2 domain. |
| DOMAIN | api[.]creativelibrary[.]top | Listed primary C2 domain. |
| DOMAIN | api[.]enable-right-click[.]click | Listed primary C2 domain. |
| DOMAIN | api[.]extensionanalyticspro[.]top | Listed primary C2 domain. |
| DOMAIN | blockfolioaddressmonitor[.]pro | Listed primary C2 domain. |
| DOMAIN | content[.]resonanceweb[.]top | Listed primary C2 domain. |
| DOMAIN | cookie-whitelist[.]com | Wallet-drainer script server identified in the related DomainTools research dataset. |
| DOMAIN | cookie-whitelist[.]top | Domain identified as hosting wallet-drainer scripts. |
| DOMAIN | cryptopricebadgequickglance[.]pro | Listed primary C2 domain. |
| DOMAIN | cryptoratesfiatconverter[.]pro | Listed primary C2 domain. |
| DOMAIN | defipulsetracker[.]pro | Listed primary C2 domain. |
| DOMAIN | enable-right-click[.]click | Listed primary C2 domain. |
| DOMAIN | extension[.]io-safe[.]icu | Listed primary C2 domain. |
| DOMAIN | feedback[.]feedx-ray[.]top | Listed primary C2 domain. |
| DOMAIN | ggle-analytics[.]com | Domain identified as serving fake wallet-restoration and browser-update content. |
| DOMAIN | lucky-random[.]sbs | Listed secondary C2 domain. |
| DOMAIN | password-protect-pdf[.]com | Listed primary C2 domain. |
| DOMAIN | payload[.]siteinsight[.]bond | Listed primary C2 domain. |
| DOMAIN | pricealarmsvolatilitywarnings[.]pro | Listed primary C2 domain. |
| DOMAIN | privatecryptonewsreader[.]pro | Listed primary C2 domain. |
| DOMAIN | relay[.]seopulsepro[.]sbs | Listed primary C2 domain. |
| DOMAIN | whale-alert[.]art | Domain identified as hosting wallet-drainer scripts. |
| DOMAIN | whale-alert[.]life | Wallet-drainer script server identified in the related DomainTools research dataset. |
| DOMAIN | ws[.]seopulsepro[.]sbs | Listed primary C2 domain. |
| DOMAIN | ws[.]site-signal[.]top | Listed primary C2 domain. |
| HOSTNAME | mimi[.]saghirmohamed19[.]workers[.]dev | Cloudflare Worker identified as a data-exfiltration sink. |
| HOSTNAME | pipi[.]saghirmohamed19[.]workers[.]dev | Cloudflare Worker identified as a data-exfiltration sink. |
MITRE ATT&CK
T1056.001 · KeyloggingA credential-grabbing module captured values entered into text, password, and email fields by hooking input-related events.T1059.007 · JavaScriptThe extensions executed downloaded JavaScript modules on visited pages through event handlers on temporary hidden DOM elements.T1071.001 · Web ProtocolsExtension service workers maintained WebSocket communications with C2 servers to receive instructions and JavaScript modules.T1105 · Ingress Tool TransferThe extension framework downloaded malicious JavaScript modules from C2 servers and stored them locally for execution.T1176.001 · Browser ExtensionsThe threat actor distributed malicious browser extensions, including extensions acquired from legitimate authors and weaponized through later updates.T1204.004 · Malicious Copy and PasteA fake browser-update page copied an attacker-supplied command to the clipboard and instructed victims to paste and run it.T1217 · Browser Information DiscoveryA dedicated module collected and exfiltrated victims' browsing history.T1528 · Steal Application Access TokenModules collected bearer or authorization tokens from logged-in tabs and Facebook access tokens.T1539 · Steal Web Session CookieAccount-harvesting modules read cookies and other authenticated session material from victims' logged-in exchange and wallet tabs.T1562.001 · Disable or Modify ToolsThe extensions registered a browser rule that removed Content Security Policy headers from visited pages to permit malicious script execution.T1573.001 · Symmetric CryptographyThe extensions encrypted received modules with AES-GCM using a key derived from the extension ID and installation UUID.
Vendors
MicrosoftWhile we primarily observed this campaign in the Chrome extension ecosystem, the discovery of the latest malicious Edge extensions proves that it has expanded to Microsoft Edge.PreppHintextension has the largest potential impact. It was initially developed by a legitimate organization, PreppHint, before eventually being acquired by the threat actor. At the time when the malicious functionality was
Products
Allow Copy - Select & Enable Right Clickinmkjedjdhgpknjogbjomhnbgdccckkg - Allow Copy - Select & Enable Right Click (Edge extension)Blockfolio: Address Monitorahpnnnjbnfbhoikhohglpohnoocjcoco - Blockfolio: Address MonitorCreative Library - Ad Spy Toolcfpnjdbpojpcongfaefcamjbaolpelcd - Creative Library - Ad Spy ToolCrypto Alerter: Price Alarms & Volatility Warningsjmlgannjlbliikgcaieomgmcnfplglea - Crypto Alerter: Price Alarms & Volatility WarningsCrypto Price Badge: Quick Glancegfackggoapepdmnjnkblogdcjpgcjiak - Crypto Price Badge: Quick GlanceCrypto Rates & Fiat Converteroeacadlaclegkkkdehjmiifnjhcekclj - Crypto Rates & Fiat ConverterDeFi Pulse Trackerlhmcajhgadanidbopgaoobjlldegjmke - DeFi Pulse TrackerEnable Right Click & Copy — Smart Unlock + OCRThe “Enable Right Click & Copy — Smart Unlock + OCR“ extension has the largest potential impact. It was initially developed by a legitimate organization, PreppHint, before eventually being acquired by the threat actor.Google ChromeThe Socket Threat Research team identified 18 Chrome extensions and 1 Edge extension sharing similarities in malicious code and malware operation techniques. The malicious versions of identified extensions wereLedgerLook: Wallet Checkerpcngchfbfgejllcbhmeadjhiebebiome - LedgerLook: Wallet CheckerMeta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Rayaodkjdeghbjiaienipfjkbpcikkacbcp - Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-RayMicrosoft EdgeWhile we primarily observed this campaign in the Chrome extension ecosystem, the discovery of the latest malicious Edge extensions proves that it has expanded to Microsoft Edge.Multi-Chain Explorerhfijkbdkpidafdbeebnnkhfccildbcle - Multi-Chain ExplorerPassword Protect PDFjamminefolhgepgihbmcjjhgldbfcikp - Password Protect PDFPixelCheckfcgdejjichpgfaaafflplhfijcnieopb - PixelCheckPrivate Crypto News Readeriekoapohahgmogbagegmcgplbkikcgke - Private Crypto News ReaderQuickLens - Search Screen with Google Lenskdenlnncndfnhkognokgfpabgkgehodd - QuickLens - Search Screen with Google LensRapidLens - Google Lens for Screen Search & Imagesfegckejpfnlmfgkfjpinlbgmeeijjkel - RapidLens - Google Lens for Screen Search & ImagesSEO Pulse Pro - Website Traffic & SEO Analyzerfjmlhlkccegopebcllcmafahkmeejpph - SEO Pulse Pro - Website Traffic & SEO AnalyzerSite Signal - Website Traffic & SEO Checkerdkdadldmiefjldmegbjbnhhfddnkhlhm - Site Signal - Website Traffic & SEO CheckerWebsite Traffic Checker: MirrorSphere SEO Statsaapdalkmclfaahehnmicbglkohkldhne - Website Traffic Checker: MirrorSphere SEO Stats