Superior: 19 Browser Extensions Steal Wallets and Passwords

Brendan Smith
Brendan Smith - Cybersecurity Analyst
7 Min Read
Nineteen extension tiles flow into a wallet trap on a black and electric orange editorial poster
Superior turned trusted-looking browser extensions into routes for wallet, password, and session theft.

Nineteen Chrome and Edge extensions in the Superior campaign could steal crypto, passwords, browser sessions, and form data. Socket says the operator built 14 extensions and took over five established ones, then delivered up to 16 malicious modules through updates. One acquired Chrome extension had about 70,000 users when it received the malicious update; a matching Edge version had about 10,000.

Those figures describe the potential install base, not 80,000 confirmed theft victims. Installing one of the extensions also does not prove that every payload ran or that a wallet was drained. The right response depends on what you did after installation.

Check your exposure before changing anything

What happened What to do now
The extension was installed, but you did not enter sensitive data or approve a wallet action Remove it from every synced browser profile, restart the browser, review other extensions, and change passwords used while it was active.
You typed a login, card number, or personal information into a page while the extension was active From a clean device, change the affected password, revoke sessions, enable MFA, and contact the card issuer if payment data was exposed.
You entered a wallet seed phrase Treat that wallet as permanently exposed. Create a new wallet on a clean device and transfer remaining assets; never reuse the old seed.
You connected a wallet or signed an unexpected transaction Review approvals and transactions, revoke suspicious token approvals, and move assets if the wallet may be compromised.
You followed a “Chrome update” prompt and ran a Terminal or PowerShell command Disconnect the device, preserve the command if possible, and run a full malware investigation. Removing the extension alone is not enough.

Which Superior extensions were identified?

Search the extension name and ID on chrome://extensions or edge://extensions. Enable Developer mode if the ID is hidden. Names can be copied by unrelated developers, so the ID is the stronger match.

Established extensions acquired by the operator

Extension ID
Enable Right Click & Copy — Smart Unlock + OCR pkoccklolohdacbfooifnpebakpbeipc
RapidLens – Google Lens for Screen Search & Images fegckejpfnlmfgkfjpinlbgmeeijjkel
QuickLens – Search Screen with Google Lens kdenlnncndfnhkognokgfpabgkgehodd
Password Protect PDF jamminefolhgepgihbmcjjhgldbfcikp
Allow Copy – Select & Enable Right Click (Edge) inmkjedjdhgpknjogbjomhnbgdccckkg
Edge Add-ons listing for Enable Right Click and Copy Smart Unlock plus OCR
Socket captured the Edge listing for the acquired right-click extension during its investigation. Source: Socket.

Extensions created for the campaign

Extension name Claimed purpose
PixelCheck Pixel and advertising checks
Creative Library – Ad Spy Tool Advertising research
Website Traffic Checker: MirrorSphere SEO Stats SEO statistics
Site Signal – Website Traffic & SEO Checker Traffic and SEO analysis
SEO Pulse Pro – Website Traffic & SEO Analyzer Traffic and SEO analysis
Private Crypto News Reader Crypto news
Blockfolio: Address Monitor Wallet monitoring
Crypto Rates & Fiat Converter Exchange rates
Crypto Alerter: Price Alarms & Volatility Warnings Price alerts
DeFi Pulse Tracker DeFi tracking
Crypto Price Badge: Quick Glance Price display
Multi-Chain Explorer Blockchain exploration
LedgerLook: Wallet Checker Wallet checking
Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray Advertising research

The five IDs above are recognition aids, not a complete indicator list for all 19 extensions. Socket’s report contains the remaining IDs and technical indicators. The campaign is separate from the earlier incident in which 25 Chrome extensions were compromised, even though both abused trusted updates.

What the malicious modules could steal

Socket found separate modules for Ethereum-compatible, Solana, and Tron wallet draining; Ledger and Trezor seed-phrase phishing; browser-session theft from exchanges and wallets; universal form and credential capture; Facebook and LinkedIn session theft; and browsing-history collection. The operator could select modules remotely rather than shipping every capability to every installation.

The ClickFix branch displayed a fake Chrome update that told the user to copy and run a command. That extra action can move the incident beyond the browser and install a system-level payload. It overlaps with the broader fake CAPTCHA and ClickFix command trap.

Research examples of a fake Ledger seed phrase form and a fake Chrome update ClickFix prompt
Research examples show two branches: a seed-phrase form and a fake browser update that asks the victim to run a command. Source: Socket.

How to remove the extensions and recover safely

  1. Record the extension name and ID. A screenshot helps an incident responder identify the affected profile and campaign branch.
  2. Remove it from Chrome or Edge. Check every browser profile and every computer where browser sync is enabled. Remove unfamiliar extensions rather than merely switching them off.
  3. Restart and recheck the browser. If the extension returns, inspect managed-browser policies and follow the browser hijacker cleanup path.
  4. Revoke sessions and rotate passwords. Do this from a clean device, starting with email, password manager, exchanges, social networks, and financial accounts.
  5. Handle wallet exposure separately. A stolen seed phrase cannot be made safe with a password change. Move assets to a new seed created on a trusted device. If you only connected a wallet, review and revoke approvals.
  6. Investigate the operating system if a command ran. Check command history, persistence, downloads, and security alerts; perform a full malware scan before using the device for sensitive accounts again.

Browser-extension removal stops that copy from running, but it cannot retract data already stolen. It also cannot remove a payload installed after a fake-update command.

Scan files downloaded from this scam.

If the page or email made you download an invoice, coupon, tracking app, browser extension, or support tool, scan the PC before opening it again or logging into sensitive accounts.

Scan this device for malware leftovers

How to verify the browser is clean

After restarting, return to the extensions page and confirm the item is gone from every profile. Review browser startup pages, search settings, notification permissions, and account sign-in activity. A clean follow-up scan and no reappearing extension are reassuring, but account and wallet recovery still matter if sensitive data was entered while the extension was active.

References

Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?