Close Menu
NCIJ Network NCIJ Network
    What's Hot

    India and Pakistan are united in spending citizen lives like pocket change | Opinions

    August 29, 2026

    Motorola Coupon Code for September 2026

    August 29, 2026

    19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • India and Pakistan are united in spending citizen lives like pocket change | Opinions
    • Motorola Coupon Code for September 2026
    • 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
    • Bitcoin ETFs Post $202M Outflow After 9-Day Inflow Run
    • A sea cucumber venture in Zanzibar seeks to balance business and conservation
    • Studying Confucius Needs Textual Expertise
    • Israel army carries out rare West Bank air strike, killing ‘three terrorists’
    • Airbus seeks US space unit sale as it shifts to European-built satellites
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 28, 2026Web Security / Supply Chain

    Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.

    The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active since February 2024. Socket is tracking the activity under the name Superior.

    The modus operandi is relatively straightforward: the threat actor either acquires legitimate extensions with proper functionality or pushes a clean version that’s devoid of any malware. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published.

    Cybersecurity

    Of the identified extensions, 14 were created by the threat actor, while the remaining five were purchased from their previous owners. The complete list of extensions is below –

    • Extensions bought by the threat actor
      • koccklolohdacbfooifnpebakpbeipc – Enable Right Click & Copy — Smart Unlock + OCR
      • fegckejpfnlmfgkfjpinlbgmeeijjkel – RapidLens – Google Lens for Screen Search & Images
      • kdenlnncndfnhkognokgfpabgkgehodd – QuickLens – Search Screen with Google Lens
      • jamminefolhgepgihbmcjjhgldbfcikp – Password Protect PDF
      • inmkjedjdhgpknjogbjomhnbgdccckkg – Allow Copy – Select & Enable Right Click (Microsoft Edge)
    • Extensions created and published by the threat actor –
      • fcgdejjichpgfaaafflplhfijcnieopb – PixelCheck
      • cfpnjdbpojpcongfaefcamjbaolpelcd – Creative Library – Ad Spy Tool
      • aapdalkmclfaahehnmicbglkohkldhne – Website Traffic Checker: MirrorSphere SEO Stats
      • dkdadldmiefjldmegbjbnhhfddnkhlhm – Site Signal – Website Traffic & SEO Checker
      • fjmlhlkccegopebcllcmafahkmeejpph – SEO Pulse Pro – Website Traffic & SEO Analyzer
      • iekoapohahgmogbagegmcgplbkikcgke – Private Crypto News Reader
      • ahpnnnjbnfbhoikhohglpohnoocjcoco – Blockfolio: Address Monitor
      • oeacadlaclegkkkdehjmiifnjhcekclj – Crypto Rates & Fiat Converter
      • jmlgannjlbliikgcaieomgmcnfplglea – Crypto Alerter: Price Alarms & Volatility Warnings

      • lhmcajhgadanidbopgaoobjlldegjmke – DeFi Pulse Tracker
      • gfackggoapepdmnjnkblogdcjpgcjiak – Crypto Price Badge: Quick Glance
      • hfijkbdkpidafdbeebnnkhfccildbcle – Multi-Chain Explorer
      • cngchfbfgejllcbhmeadjhiebebiome – LedgerLook: Wallet Checker
      • aodkjdeghbjiaienipfjkbpcikkacbcp – Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray

    It’s worth highlighting that the “QuickLens – Search Screen with Google Lens” was previously flagged by both Annex Security and monxresearch-sec earlier this year, detailing its ability to push malware to downstream customers, inject arbitrary code, and harvest sensitive data.

    The latest findings from Socket suggest that the activity is broader in scope than previously thought and has been ongoing since February 2024. Some aspects of this campaign were documented by DomainTools Investigations in May 2025.

    At the time, the threat actor was observed creating fake websites masquerading as legitimate services, productivity tools, ad and media creation or analysis assistants, VPN services, cryptocurrency or banking utilities to trick users into installing malicious extensions from the Chrome Web Store.

    “The extensions typically have a dual functionality, in which they generally appear to function as intended, but also connect to malicious servers to send user data, receive commands, and execute arbitrary code,” DomainTools Investigations said.

    The extension with the most potential impact is “Enable Right Click & Copy — Smart Unlock + OCR,” which has a collective install base of 80,000 users across both Chrome and Edge browsers. Each of the extensions also supports the ability to establish contact with a command-and-control (C2) server and set up a persistent WebSocket connection.

    “Worth noting is that the loading framework supports rotation of the C2 endpoint based on instructions received from the initial C2 server and this behavior has been observed in the wild,” Zanki explained.

    “That functionality enables threat actors to distribute victims to different groups and dedicated C2 infrastructure and to reduce the detection risk. Data exfiltration endpoint is also dynamically received from the C2 instructions enabling a per-victim exfiltration channel.”

    Cybersecurity

    As observed in the case of QuickLens, the malicious code embedded in the extensions strips Content Security Policy (CSP) headers from every page and facilitates the injection of JavaScript code modules on targeted websites using content scripts. A total of 16 modules have been identified. They span the following categories –

    • Multi-chain wallet drainer
    • Hardware-wallet seed-phrase harvester
    • Cryptocurrency exchange and wallet account harvester
    • Universal credential or form grabber
    • Facebook and LinkedIn account stealers
    • Browser history stealer
    • ClickFix-style lure

    The ClickFix module injects a fake web browser update and employs operating system-specific instructions to get the user to copy and paste the malicious command.

    Exactly who is behind the campaign remains unknown. But the fact that they have been successfully operating for more than two years points to a “very capable threat actor.”

    “The biggest risk for end-users is the operational technique in which the threat actor successfully acquires legitimate extensions and releases new versions empowered with malicious functionality,” Zanki said. “That approach, combined with Chrome’s default extension update settings, performs auto-updating to the latest version of extension, providing the threat actor with a powerful vector to maximize the impact and reach of the extension acquisition.”

    Chrome Code CryptoDraining Edge extensions WalletStealing
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Motorola Coupon Code for September 2026

    GiveWP WordPress donation plugin flaw lets hackers execute server commands

    Brave’s browser one-ups Chrome with its new support for email aliases

    The Vulnpocalypse Is Repricing the Bug Bounty Economy

    ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

    You Need Cyber Deception for OT

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    India and Pakistan are united in spending citizen lives like pocket change | Opinions

    August 29, 2026

    Motorola Coupon Code for September 2026

    August 29, 2026

    19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

    August 29, 2026

    Bitcoin ETFs Post $202M Outflow After 9-Day Inflow Run

    August 29, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    India and Pakistan are united in spending citizen lives like pocket change | Opinions

    August 29, 2026

    Motorola Coupon Code for September 2026

    August 29, 2026

    19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.