Security1 distinct publisher2 min readPublished
Socket found 19 Chrome and Edge extensions carrying crypto-draining code, five of them bought from their original owners. The malware landed in updates after each listing had earned real installs, which is exactly what a one-time vetting pass never re-checks.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The buy is the tell. The actor could have created all nineteen listings itself, and did create fourteen; for the other five it paid the previous owners [4]. A listing that already carries an install base and a review history is worth money because a fresh upload has none of that and has to earn it. The highest-impact extension in the set, Enable Right Click & Copy - Smart Unlock + OCR, came with its users already attached [6].
Allowlisting rests on a reviewed extension ID staying what it was reviewed as. The ID is stable while the code served under it changes with every update, and the poisoned version reaches everyone who already installed the clean one [5]. An allowlist keyed to the extension ID keeps trusting it straight through the release that turns hostile.
In the QuickLens listing, the malicious code strips Content Security Policy headers from every page it touches [12], removing the browser's own limit on where an injected script can send what it collects.
None of this is a single bad upload. QuickLens was flagged this year by Annex Security and monxresearch-sec [7], and DomainTools mapped the campaign's fake-service websites back in May 2025 [8]. Socket, which calls the operation Superior [2], reads the same operating model running since February 2024 [3]. Several research teams, one method, more than two years of it.
Five acquisitions out of nineteen [13] is a small sample, but the acquisitions are the part that defeats the trust model, because they arrive pre-approved. The checks that survive are the ones that re-run on each published build. In practice that means pinning the version you reviewed, or treating every auto-update as a new and unreviewed extension.
Ranked by verification strength, evidence, and original report placement.
Socket discovered a cluster of 18 Google Chrome and one Microsoft Edge extension, 19 in total, carrying wallet-secret-stealing and cryptocurrency-draining code, all published over the past six months.
Socket security researcher Karlo Zanki analyzed the extensions, and Socket tracks the activity under the name Superior.
Evidence indicates the campaign may have been active since February 2024.
Fourteen of the extensions were created and published by the threat actor, and the remaining five were purchased from their previous owners.
The threat actor either acquires legitimate functioning extensions or publishes a clean version with no malware, then once the extension gathers user downloads publishes a new version that adds the malicious behavior.
The extension with the most potential impact, Enable Right Click & Copy - Smart Unlock + OCR, has a collective install base of 80,000 users across Chrome and Edge.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Chrome's auto-update default distributed the drainer once the extension changed hands1 distinct publisher
security
Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume1 distinct publisher
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
build
Wrapping a web tool in VS Code: four sandbox rules, and two gaps in the published fix1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, one vendor, 19 checkable IDs
The mechanism claims are specific enough to be falsified by anyone with a browser: every extension is named with its store ID, and the CSP stripping, WebSocket C2 and endpoint rotation are attributed on the record to Zanki. What keeps this from scoring higher is that The Hacker News is relaying Socket rather than reproducing it, and the two supporting references — Annex Security and monxresearch-sec on QuickLens, DomainTools on the fake-site funnel — reach us only as citations inside that relay. The February 2024 start date is the softest link in the chain; even Socket only says the evidence 'may' point there.
80,000 on the biggest listing, silence on the other 18
Reach is documented exactly once. We know the right-click unlocker sits near 80,000 combined Chrome and Edge users; for the remaining eighteen listings there is no install count, no victim tally, and no drained-wallet figure. Against that, the delivery path is real rather than theoretical — DomainTools watched the fake-site funnel operating in May 2025, and rotating C2 endpoints were seen in the wild, so this is a live campaign with at least one meaningfully installed listing, not a lab finding.
Sober mechanics, absent consequences
The write-up largely resists inflation: no 'millions at risk', no invented victim numbers, and the actor is called 'very capable' rather than given a flag or a nation. The overhang is in the shape of the story rather than its adjectives — nineteen listings and sixteen injection modules imply a wide blast radius, while the only quantified impact anywhere is 80,000 installs on one extension, with no losses attached. A reader could easily finish this with a bigger picture in mind than the numbers actually license.
The finder sells the fix
Socket's business is scanning package and extension supply chains, and this is a Socket disclosure with a Socket-coined campaign name attached; naming an operation 'Superior' is research and branding at the same time. That does not make the store IDs wrong — they are checkable — but the framing choice to lead on Chrome's silent auto-update, the one problem a continuous scanner addresses, aligns neatly with the vendor's product. The Hacker News adds a second layer: aggregator coverage of vendor research runs on the vendor's own framing by default.
Firm on how, blank on how much
We would defend the mechanism without hesitation: acquisition, clean listing, malicious version bump, rotating C2, per-victim exfiltration. We would not defend any statement about scale, dollars, or who is behind it, and we cannot say from this reporting whether the extensions are still installable today. One publisher, one vendor, no platform response — enough to act on as an operator, not enough to treat the numbers as settled.