Security firm Socket Inc. disclosed in August 2026 that 19 Chrome and Edge extensions had been quietly delivering a shared malware framework tracked as “Superior.” Eighteen extensions targeted Chrome, one targeted Edge. Roughly 80,000 users were exposed. The campaign had been evolving since at least February 2024.
Trusted Tools, Poisoned Updates
Attackers didn’t need you to click anything suspicious — they just needed you to have already installed their extension.
Attackers either built 14 of the 19 extensions themselves — legitimate-looking utilities that worked as advertised — or bought five existing extensions from real developers and quietly poisoned them through the normal auto-update channel. Think of it like a beloved neighborhood restaurant selling to new owners who kept the menu identical while replacing everything in the kitchen. Same sign. Very different food.
Once installed, Superior’s 16-module framework waited, then activated. According to Socket’s research, the malware loaded modules dynamically via encrypted connections to attacker-controlled domains, including cookie-whitelist.top and whale-alert.art. Here’s what it actually did:
- Hijacked “Connect Wallet” and “Swap” buttons on crypto sites, so users unknowingly signed attacker-controlled transactions across Ethereum, Solana, and Tron wallets
- Stole session tokens — not passwords — from Coinbase, Binance, Kraken, MetaMask, OKX, and others, enabling account takeover without triggering standard login alerts
- Injected fake Ledger and Trezor recovery prompts designed to capture seed phrases
- Beyond crypto, the framework scraped browsing history and harvested credentials from Facebook and LinkedIn login forms, and displayed fake browser-update prompts to unlock additional attack stages
Extensions “delivering an extendable malware framework” were updated after gaining user trust, not submitted as obviously malicious from the start. — Socket Inc. research report, August 2026
The clearest example: “Enable Right Click & Copy – Smart Unlock + OCR” reached 70,000 Chrome users and 10,000 Edge users before removal. One mundane utility. Massive blast radius. Store removal doesn’t fix it — if that extension is still sitting in your browser bar, it can continue to communicate with attacker servers and run malware modules until you remove it locally.
How Attackers Weaponized Chrome’s Own Security Layer
Google’s Manifest V3 was introduced to reduce this kind of risk, but the Superior campaign found the gaps.
Replacing powerful network-interception APIs with more limited declarative rules, Manifest V3 didn’t close every door. Attackers abused Chrome’s declarativeNetRequest API — a legitimate tool — to strip page-level security defenses, then injected malicious JavaScript into every site visited, according to analysis by The Hacker News and Daily.dev covering Socket’s report.
This isn’t isolated. “Save Image as Type,” a Chrome extension with over one million users, was separately discovered hijacked for affiliate-commission fraud and browsing-data collection, according to 9to5Google. That case also showed how fragmented store responses can be — Edge removed the extension months before Chrome acted. Apps built as a surveillance app have followed a similar pattern of appearing legitimate while covertly harvesting user data.
This is abusing Chrome’s own security architecture. — security analysis summarized in Daily.dev’s coverage of the Socket report
Google and Microsoft pulled the 19 Superior extensions following Socket’s disclosure, but extensions don’t uninstall themselves. The Edge version of “Enable Right Click & Copy” reportedly continued pushing malicious updates for a period even after Chrome’s listing was pulled, per TechSpot reporting. Store removal is the beginning of the story, not the end.
Immediate Steps for Affected Users
Manual removal and session hygiene are the only reliable fixes — don’t wait for your browser to do it for you.
Open your browser’s extension manager and check against Socket Inc.’s published list of 19 flagged add-ons — including RapidLens, QuickLens, Password Protect PDF, Blockfolio Address Monitor, and Crypto Alerter — then remove any matches immediately. For more on hidden digital attack vectors and how to stay safe, reviewing common hardware and software risks is a useful next step.
If you saw unusual wallet prompts or signed transactions you don’t recognize, revoke active sessions on every exchange, rotate passwords, and treat your seed phrase as compromised. The attack was silent by design. That doesn’t mean the damage was.





























