
Superior Actor's 19 Extensions Steal Wallet Secrets via Updated Chrome and Edge Store Listings
The Superior campaign demonstrates sustained supply-chain compromise of browser extensions targeting cryptocurrency users. Evidence from Socket, DomainTools, and earlier Annex reports shows the operation began no later than February 2024 and evaded store defenses through purchased extensions and incremental malicious updates. Store operators must improve post-publication behavioral monitoring to limit further financial losses.
Socket researcher Karlo Zanki identified the Superior cluster through code overlap and tradecraft markers across 19 extensions. Fourteen were created outright by the actor; five were purchased after gaining legitimate downloads, then updated with malicious payloads. All maintain WebSocket connections to rotating C2 endpoints that receive commands to exfiltrate seed phrases and execute drains. DomainTools documented the same actor in May 2025 using fake productivity and crypto-utility sites to drive installs. Annex Security and monxresearch-sec had already flagged QuickLens for arbitrary code execution earlier in 2025, yet store review processes allowed the remaining 18 extensions to persist for months. The campaign therefore exceeds prior single-extension reports in both duration and scale. The dual-function model—benign appearance followed by silent updates—exploits Chrome Web Store and Edge Add-ons verification gaps. Extension acquisition from prior owners further obscures attribution and bypasses initial vetting. Persistent C2 rotation and WebSocket persistence indicate operational maturity and intent to maintain access across user bases. Google and Microsoft have not issued takedown timelines. Continued monitoring of extension update graphs and C2 infrastructure will determine whether the actor shifts to new developer accounts or new store categories.
Google: 12 or more Superior-linked extensions removed from the Chrome Web Store by 15 October 2025
Sources (3)
- [1]The Hacker News(https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html)
- [2]DomainTools Investigations(https://www.domaintools.com/blog/2025/05/superior-threat-actor-fake-extension-sites/)
- [3]Socket Research(https://socket.dev/blog/superior-campaign-chrome-edge-extensions)