Skip to main content
AVOID.NET

19-Extension Chrome/Edge Wallet Drainer Batch (September 2026)

avoid.net/19-extension-chrome-edge-wallet-drainer-batch-september-20263/100·75% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

In late August 2026, security researchers at Socket published research identifying 19 Chrome and Edge browser extensions sharing a common modular malware framework, tracked internally as "Superior," that could drain multi-chain cryptocurrency wallets, steal hardware-wallet seed phrases, and hijack exchange sessions. Fourteen of the extensions were allegedly created directly by the threat actor as clean, functional tools that later received malicious updates, while five — including the QuickLens extension previously flagged in a separate March 2026 incident — were allegedly acquired from legitimate developers before being weaponized. The campaign's infrastructure and code allegedly trace back to at least February 2024, making it a longer-running and broader operation than the single-extension QuickLens incident that first drew public attention.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about 19-Extension Chrome/Edge Wallet Drainer Batch (September 2026)?

Timeline(8 events)

February 2024

Code and infrastructure later linked to the "Superior" campaign are alleged by Socket to have first become active, based on similarities identified in retrospect.

The Hacker News

1 February 2026

Ownership of the QuickLens extension allegedly transferred to a new registrant.

BleepingComputer

17 February 2026

QuickLens version 5.8 is released containing malicious ClickFix and credential/wallet-theft code.

BleepingComputer

February 2026

Security researchers at Annex publicly report the QuickLens compromise; the extension is subsequently removed.

SC Media

August 2026

The Edge version of "Enable Right Click & Copy — Smart Unlock + OCR" reportedly receives an update pointing to a new C2 domain, after the Chrome version had already been flagged.

CyberInsider

August 2026

Socket publishes research identifying 19 Chrome and Edge extensions sharing the "Superior" malware framework.

The Hacker News

1 September 2026

The Daily Hodl reports Google has pulled affected Chrome listings.

The Daily Hodl

September 2026

Gridinsoft publishes an updated analysis of the Superior campaign with the full list of 19 extension names.

Gridinsoft
Provenance & Audit Trail
6 Wayback Archives

6 of 7 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/19/2026, 12:12:28 PM

last updated: 9/19/2026, 2:10:18 PM

avoid.net — verified advice for a post-truth world