Nineteen browser extensions have been linked to a malware operation that steals cryptocurrency wallet secrets, passwords and other data.
The extensions appeared to offer useful tools, including search helpers, price monitors and copy-unlocking features, before later updates quietly introduced the harmful code.
The campaign affects 18 Chrome extensions and one Microsoft Edge extension. Attackers acquired established add-ons with existing users, then used routine automatic updates to deliver harmful new versions. The most exposed pair potentially reached 80,000 users.
Researchers at Socket.dev identified the operation and said the related extensions share a flexible framework for downloading and running fresh payloads.
Socket.dev said in a report shared with Cyber Security News (CSN) that the campaign mainly pursues wallet theft and cryptocurrency draining, but can also collect credentials, session data and browsing history.

The findings show why an extension is not safe simply because it began legitimate. Code added after publication turned familiar tools into a route for theft, echoing the concerns in compromised Chrome extension campaigns involving browser add-ons that were later weaponized.
19 Chrome and Edge Extensions Caught Stealing
Socket tracked the operation as Superior, based on labels used in its JavaScript modules. Fourteen of the extensions were created by the actors, while five were reportedly bought from legitimate developers.
The clean first releases built trust; later updates added the malware, an approach that can leave users unaware that ownership and risk have changed.
The most exposed listing was Enable Right Click & Copy – Smart Unlock + OCR. Google removed its Chrome version after it was identified, but the research said the matching Edge version was still active and delivering malware at the time of publication.
That distinction matters because removing one store listing does not automatically remove an installed add-on or stop a related version elsewhere.
The software opens an encrypted WebSocket channel to attacker-controlled infrastructure and receives code modules for particular tasks. It can also rotate to a replacement control server and use a separate destination for stolen data.
This layered design makes simple disruption harder and lets the operators change behavior without publishing a visibly different extension.
One key technique removes the browser’s Content Security Policy header from pages a victim visits. That safeguard normally limits which scripts a website can load.
With it gone, the extension can inject code into pages and trigger it through hidden page elements, repeating a tactic described in coverage of malicious Chrome security bypasses.
Wallet Drainers and Password Theft
The downloaded modules target several high-value paths. A wallet drainer detects EVM, Solana and Tron wallets, then replaces genuine Connect Wallet or Swap button behavior with attacker-controlled approval requests.
Another module presents convincing recovery or update screens to capture seed phrases, which can give criminals complete control of a wallet.
Other modules target logged-in exchange and wallet sessions, collecting cookies, access tokens, profile information and balances from services including Coinbase, Binance, Kraken and MetaMask.

A universal form grabber records text, email and password fields across visited sites. That breadth raises the stakes beyond crypto: personal accounts and workplace logins may also be exposed.
The campaign also includes social-media data theft, browsing-history collection and fake browser-update prompts. Those prompts can copy an attacker command to the clipboard and tell a victim to paste it into their computer.
Readers should treat unexpected update instructions as suspicious, especially when a website asks them to run a command, as shown by recent fake wallet update lures.
Users should review installed extensions now, remove those they do not need and examine any add-on that recently changed publisher or permissions.
People who used an affected extension should change passwords from a clean device, revoke active sessions where possible and move cryptocurrency to a new wallet if a recovery phrase may have been entered.
Teams should inventory browser extensions and watch for unusual outbound connections, applying lessons from malicious Firefox add-on investigations.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| C2 domain | active-enable-right-click[.]top |
Primary command-and-control domain |
| C2 domain | api[.]enable-right-click[.]click |
Primary command-and-control domain |
| C2 domain | enable-right-click[.]click |
Primary command-and-control domain |
| C2 domain | payload[.]siteinsight[.]bond |
Primary command-and-control domain |
| C2 domain | api[.]extensionanalyticspro[.]top |
Primary command-and-control domain |
| C2 domain | password-protect-pdf[.]com |
Primary command-and-control domain |
| C2 domain | privatecryptonewsreader[.]pro |
Primary command-and-control domain |
| C2 domain | cryptoratesfiatconverter[.]pro |
Primary command-and-control domain |
| C2 domain | cryptopricebadgequickglance[.]pro |
Primary command-and-control domain |
| C2 domain | ws[.]site-signal[.]top |
Primary command-and-control domain |
| C2 domain | content[.]resonanceweb[.]top |
Primary command-and-control domain |
| C2 domain | api[.]creativelibrary[.]top |
Primary command-and-control domain |
| C2 domain | api[.]codefilearc[.]net |
Primary command-and-control domain |
| C2 domain | ws[.]seopulsepro[.]sbs |
Primary command-and-control domain |
| C2 domain | relay[.]seopulsepro[.]sbs |
Primary command-and-control domain |
| C2 domain | defipulsetracker[.]pro |
Primary command-and-control domain |
| C2 domain | blockfolioaddressmonitor[.]pro |
Primary command-and-control domain |
| C2 domain | pricealarmsvolatilitywarnings[.]pro |
Primary command-and-control domain |
| C2 domain | extension[.]io-safe[.]icu |
Primary command-and-control domain |
| C2 domain | feedback[.]feedx-ray[.]top |
Primary command-and-control domain |
| Secondary C2 domain | lucky-random[.]sbs |
Secondary command-and-control endpoint |
| Exfiltration domain | pipi[.]saghirmohamed19[.]workers[.]dev |
Cloudflare Worker data-exfiltration sink |
| Exfiltration domain | mimi[.]saghirmohamed19[.]workers[.]dev |
Cloudflare Worker data-exfiltration sink |
| Payload-hosting domain | cookie-whitelist[.]top |
Wallet drainer script hosting |
| Payload-hosting domain | whale-alert[.]art |
Wallet drainer script hosting |
| Payload-hosting domain | ggle-analytics[.]com |
Fake browser-update page hosting |
| Related domain | cookie-whitelist[.]com |
Related domain reported in DomainTools research |
| Related domain | whale-alert[.]life |
Related domain reported in DomainTools research |
| Chrome extension ID | pkoccklolohdacbfooifnpebakpbeipc |
Enable Right Click & Copy – Smart Unlock + OCR |
| Chrome extension ID | fegckejpfnlmfgkfjpinlbgmeeijjkel |
RapidLens – Google Lens for Screen Search & Images |
| Chrome extension ID | kdenlnncndfnhkognokgfpabgkgehodd |
QuickLens – Search Screen with Google Lens |
| Chrome extension ID | jamminefolhgepgihbmcjjhgldbfcikp |
Password Protect PDF |
| Edge extension ID | inmkjedjdhgpknjogbjomhnbgdccckkg |
Allow Copy – Select & Enable Right Click |
| Chrome extension ID | fcgdejjichpgfaaafflplhfijcnieopb |
PixelCheck |
| Chrome extension ID | cfpnjdbpojpcongfaefcamjbaolpelcd |
Creative Library – Ad Spy Tool |
| Chrome extension ID | aapdalkmclfaahehnmicbglkohkldhne |
Website Traffic Checker: MirrorSphere SEO Stats |
| Chrome extension ID | dkdadldmiefjldmegbjbnhhfddnkhlhm |
Site Signal – Website Traffic & SEO Checker |
| Chrome extension ID | fjmlhlkccegopebcllcmafahkmeejpph |
SEO Pulse Pro – Website Traffic & SEO Analyzer |
| Chrome extension ID | iekoapohahgmogbagegmcgplbkikcgke |
Private Crypto News Reader |
| Chrome extension ID | ahpnnnjbnfbhoikhohglpohnoocjcoco |
Blockfolio: Address Monitor |
| Chrome extension ID | oeacadlaclegkkkdehjmiifnjhcekclj |
Crypto Rates & Fiat Converter |
| Chrome extension ID | jmlgannjlbliikgcaieomgmcnfplglea |
Crypto Alerter: Price Alarms & Volatility Warnings |
| Chrome extension ID | lhmcajhgadanidbopgaoobjlldegjmke |
DeFi Pulse Tracker |
| Chrome extension ID | gfackggoapepdmnjnkblogdcjpgcjiak |
Crypto Price Badge: Quick Glance |
| Chrome extension ID | hfijkbdkpidafdbeebnnkhfccildbcle |
Multi-Chain Explorer |
| Chrome extension ID | pcngchfbfgejllcbhmeadjhiebebiome |
LedgerLook: Wallet Checker |
| Chrome extension ID | aodkjdeghbjiaienipfjkbpcikkacbcp |
Meta & Facebook Ad Library Spy – Save Ads, Finder, Downloader | FeedX-Ray |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post 19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords appeared first on Cyber Security News.
