{"investigation":{"slug":"19-extension-chrome-edge-wallet-drainer-batch-september-2026","entity_name":"19-Extension Chrome/Edge Wallet Drainer Batch (September 2026)","trust_score":3,"severity_base":null,"score_modifier":0,"confidence":0.75,"status":"draft","content_type":"investigation","summary":"In late August 2026, security researchers at Socket published research identifying 19 Chrome and Edge browser extensions sharing a common modular malware framework, tracked internally as \"Superior,\" that could drain multi-chain cryptocurrency wallets, steal hardware-wallet seed phrases, and hijack exchange sessions. Fourteen of the extensions were allegedly created directly by the threat actor as clean, functional tools that later received malicious updates, while five — including the QuickLens extension previously flagged in a separate March 2026 incident — were allegedly acquired from legitimate developers before being weaponized. The campaign's infrastructure and code allegedly trace back to at least February 2024, making it a longer-running and broader operation than the single-extension QuickLens incident that first drew public attention.","sections":[{"content":"On or around August 27-28, 2026, researchers at the software supply-chain security firm Socket published findings describing 19 Chrome and Edge browser extensions that shared a single modular malware framework. Socket's researcher Karlo Zanki tracked the operation under the internal name \"Superior,\" based on labels found within the malicious JavaScript modules themselves. According to Socket, the identity of the threat actor behind the campaign remains unknown, though the operation's multi-year longevity was described as indicating a capable and well-resourced actor. This attribution has not been independently confirmed by another security firm at the time of writing, so it should be treated as Socket's assessment rather than an established fact.","heading":"Discovery and Attribution","sources":[{"url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","name":"The Hacker News — \"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code\"","type":"news_article","credibility":2},{"url":"https://blog.gridinsoft.com/superior-malicious-browser-extensions/","name":"Gridinsoft — \"Superior: 19 Malicious Browser Extensions\"","type":"research","credibility":2}],"severity":"high"},{"content":"Reporting on Socket's research states that of the 19 identified extensions, 14 were allegedly built and published directly by the threat actor as legitimate-seeming, functional tools (e.g., SEO trackers, ad-library viewers, crypto price tickers) that accumulated user trust and installs before receiving malicious updates. The remaining five extensions were allegedly purchased from their original, legitimate developers and subsequently weaponized via an update pushed through the Chrome/Edge auto-update mechanism. Named extensions reported across multiple outlets include \"Enable Right Click & Copy — Smart Unlock + OCR,\" \"RapidLens – Google Lens for Screen Search & Images,\" \"QuickLens – Search Screen with Google Lens,\" \"Password Protect PDF,\" and \"Allow Copy – Select & Enable Right Click\" (the acquired group), alongside created extensions such as \"Private Crypto News Reader,\" \"DeFi Pulse Tracker,\" \"LedgerLook: Wallet Checker,\" \"Multi-Chain Explorer,\" and others themed around crypto-price tracking and SEO/traffic analytics. This acquisition-then-weaponization pattern mirrors known browser-extension supply-chain attack techniques reported elsewhere in the industry, though the specific extension list and campaign attribution rest on Socket's research and its syndication by secondary outlets rather than on court records or regulatory findings.","heading":"Acquisition and Supply-Chain Method","sources":[{"url":"https://blog.gridinsoft.com/superior-malicious-browser-extensions/","name":"Gridinsoft — \"Superior: 19 Malicious Browser Extensions\" (extension list)","type":"research","credibility":2},{"url":"https://dailyhodl.com/2026/09/01/malware-discovered-in-19-google-chrome-browser-extensions-as-hackers-push-to-drain-crypto-and-harvest-data/","name":"The Daily Hodl — \"Malware Discovered In 19 Google Chrome Browser Extensions\"","type":"news_article","credibility":2},{"url":"https://cyberinsider.com/19-chrome-and-edge-extensions-caught-harvesting-crypto-wallet-seeds/","name":"CyberInsider — \"19 Chrome and Edge extensions caught harvesting crypto wallet seeds\"","type":"news_article","credibility":2}],"severity":"high"},{"content":"According to Socket's research as reported by multiple outlets, the malware framework included approximately 16 distinct modules. Alleged capabilities include a multi-chain wallet drainer targeting EVM-compatible chains, Solana, and Tron; fake Ledger and Trezor hardware-wallet recovery pages designed to phish 12-, 18-, or 24-word seed phrases; and session-hijacking modules targeting authenticated logins on Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask, allegedly collecting session cookies, authorization tokens, account information, and balance data. Additional modules reportedly stripped Content-Security-Policy and X-Frame-Options headers via the declarativeNetRequest API to enable injected malicious scripts, established an encrypted WebSocket command-and-control channel, exfiltrated browser history and form data, and harvested Facebook/LinkedIn credentials. These are Socket's technical findings as relayed by secondary reporting; AVOID.NET has not independently reviewed the malware code or Socket's full technical writeup.","heading":"Malicious Capabilities Targeting Crypto Wallets","sources":[{"url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","name":"The Hacker News — \"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code\"","type":"news_article","credibility":2},{"url":"https://cybersecuritynews.com/extensions-caught-stealing-crypto-wallets-and-passwords/","name":"CyberSecurityNews — \"19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords\"","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Reporting indicates that the extension with the largest install base, \"Enable Right Click & Copy — Smart Unlock + OCR\" (originally developed by a company referred to as PreppHint before its alleged acquisition by the threat actor), had roughly 70,000 users on Chrome and roughly 10,000 users on Edge at the time malicious code was reportedly introduced — a combined figure of approximately 80,000 that several outlets cited as the campaign's headline exposure number. It is important to note, as one outlet explicitly clarified, that these figures describe potential install base rather than confirmed victims of theft; no outlet reviewed reported a verified count of wallets actually drained or funds actually lost. Google reportedly removed the malicious Chrome listing for this extension after detection. As of Socket's report, the Microsoft Edge version reportedly remained live and had received an update on August 14, 2026 pointing to a new command-and-control domain, meaning it may have continued operating past the Chrome takedown. No public statement from Google or Microsoft was found addressing the broader 19-extension campaign at the time of writing.","heading":"Scale of Exposure and Confirmed Removals","sources":[{"url":"https://cyberinsider.com/19-chrome-and-edge-extensions-caught-harvesting-crypto-wallet-seeds/","name":"CyberInsider — \"19 Chrome and Edge extensions caught harvesting crypto wallet seeds\"","type":"news_article","credibility":2},{"url":"https://dailyhodl.com/2026/09/01/malware-discovered-in-19-google-chrome-browser-extensions-as-hackers-push-to-drain-crypto-and-harvest-data/","name":"The Daily Hodl — \"Malware Discovered In 19 Google Chrome Browser Extensions\"","type":"news_article","credibility":2}],"severity":"high"},{"content":"QuickLens (\"QuickLens – Search Screen with Google Lens\") was reported as a standalone incident beginning in mid-February 2026, when security researchers at Annex identified that the extension — a Google Lens search tool with roughly 7,000 users that had previously carried a Google \"featured\" badge — had changed ownership around February 1, 2026 (registered to an entity using the contact support@doodlebuggle.top under the name \"LLC Quick Lens\") and then shipped a malicious version 5.8 on February 17, 2026. That version allegedly stripped security headers, displayed fake Google Update prompts leading to \"ClickFix\" style attacks that tricked Windows users into running a malicious googleupdate.exe and hidden PowerShell commands, and targeted seed-phrase theft from at least 11 wallets including MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Solflare, Backpack, Brave Wallet, Exodus, Binance Chain Wallet, and WalletConnect. Socket's later August 2026 research allegedly identified QuickLens as one of five extensions that had been acquired and weaponized as part of the larger 19-extension \"Superior\" framework, indicating that QuickLens was not an isolated incident but reportedly one component of a longer-running, broader supply-chain campaign dating back to at least February 2024. This link is based on Socket's own characterization and has not been corroborated by a third, independent research source found during this investigation.","heading":"Relationship to the QuickLens Incident","sources":[{"url":"https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/","name":"BleepingComputer — \"QuickLens Chrome extension steals crypto, shows ClickFix attack\"","type":"news_article","credibility":1},{"url":"https://www.scworld.com/brief/malicious-chrome-extension-quicklens-removed-after-stealing-crypto-and-spreading-malware","name":"SC Media — \"Chrome extension 'QuickLens' removed after stealing crypto and spreading malware\"","type":"news_article","credibility":1},{"url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","name":"The Hacker News — \"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code\"","type":"news_article","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2024-02","event":"Code and infrastructure later linked to the \"Superior\" campaign are alleged by Socket to have first become active, based on similarities identified in retrospect.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"},{"date":"2026-02-01","event":"Ownership of the QuickLens extension allegedly transferred to a new registrant.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/","date_evidence":"the owner changing to support@doodlebuggle.top under \"LLC Quick Lens\" on February 1, 2026"},{"date":"2026-02-17","event":"QuickLens version 5.8 is released containing malicious ClickFix and credential/wallet-theft code.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/","date_evidence":"Version 5.8, released February 17, 2026, introduced multiple attack vectors."},{"date":"2026-02","event":"Security researchers at Annex publicly report the QuickLens compromise; the extension is subsequently removed.","source":"SC Media","source_url":"https://www.scworld.com/brief/malicious-chrome-extension-quicklens-removed-after-stealing-crypto-and-spreading-malware"},{"date":"2026-08","event":"The Edge version of \"Enable Right Click & Copy — Smart Unlock + OCR\" reportedly receives an update pointing to a new C2 domain, after the Chrome version had already been flagged.","source":"CyberInsider","source_url":"https://cyberinsider.com/19-chrome-and-edge-extensions-caught-harvesting-crypto-wallet-seeds/","date_evidence":"an update pushed on August 14 to a new command-and-control domain","date_original":"2026-08-14"},{"date":"2026-08","event":"Socket publishes research identifying 19 Chrome and Edge extensions sharing the \"Superior\" malware framework.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","date_original":"2026-08-27"},{"date":"2026-09-01","event":"The Daily Hodl reports Google has pulled affected Chrome listings.","source":"The Daily Hodl","source_url":"https://dailyhodl.com/2026/09/01/malware-discovered-in-19-google-chrome-browser-extensions-as-hackers-push-to-drain-crypto-and-harvest-data/","date_evidence":"Malware Discovered In 19 Google Chrome Browser Extensions As Hackers Push To Drain Crypto and Harvest Data (published September 1, 2026)"},{"date":"2026-09","event":"Gridinsoft publishes an updated analysis of the Superior campaign with the full list of 19 extension names.","source":"Gridinsoft","source_url":"https://blog.gridinsoft.com/superior-malicious-browser-extensions/","date_original":"2026-09-02"}],"sources_used":[{"url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","name":"The Hacker News — \"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code\"","type":"news_article","archive_url":"http://web.archive.org/web/20260911201237/https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","credibility":2,"archive_timestamp":"2026-09-11T20:12:37+00:00"},{"url":"https://cyberinsider.com/19-chrome-and-edge-extensions-caught-harvesting-crypto-wallet-seeds/","name":"CyberInsider — \"19 Chrome and Edge extensions caught harvesting crypto wallet seeds\"","type":"news_article","archive_url":"http://web.archive.org/web/20260831121938/https://cyberinsider.com/19-chrome-and-edge-extensions-caught-harvesting-crypto-wallet-seeds/","credibility":2,"archive_timestamp":"2026-08-31T12:19:38+00:00"},{"url":"https://cybersecuritynews.com/extensions-caught-stealing-crypto-wallets-and-passwords/","name":"CyberSecurityNews — \"19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords\"","type":"news_article","archive_url":"http://web.archive.org/web/20260911215544/https://cybersecuritynews.com/extensions-caught-stealing-crypto-wallets-and-passwords/","credibility":2,"archive_timestamp":"2026-09-11T21:55:44+00:00"},{"url":"https://dailyhodl.com/2026/09/01/malware-discovered-in-19-google-chrome-browser-extensions-as-hackers-push-to-drain-crypto-and-harvest-data/","name":"The Daily Hodl — \"Malware Discovered In 19 Google Chrome Browser Extensions\"","type":"news_article","archive_url":"http://web.archive.org/web/20260903022551/https://dailyhodl.com/2026/09/01/malware-discovered-in-19-google-chrome-browser-extensions-as-hackers-push-to-drain-crypto-and-harvest-data/","credibility":2,"archive_timestamp":"2026-09-03T02:25:51+00:00"},{"url":"https://blog.gridinsoft.com/superior-malicious-browser-extensions/","name":"Gridinsoft — \"Superior: 19 Malicious Browser Extensions\"","type":"research","archive_url":"http://web.archive.org/web/20260919125308/https://blog.gridinsoft.com/superior-malicious-browser-extensions/","credibility":2,"archive_timestamp":"2026-09-19T12:53:08+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/","name":"BleepingComputer — \"QuickLens Chrome extension steals crypto, shows ClickFix attack\"","type":"news_article","archive_url":"http://web.archive.org/web/20260830200917/https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/","credibility":1,"archive_timestamp":"2026-08-30T20:09:17+00:00"},{"url":"https://www.scworld.com/brief/malicious-chrome-extension-quicklens-removed-after-stealing-crypto-and-spreading-malware","name":"SC Media — \"Chrome extension 'QuickLens' removed after stealing crypto and spreading malware\"","type":"news_article","archive_url":null,"credibility":1,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-09-19T12:12:28.260967+00:00","updated_at":"2026-09-19T14:10:18.631623+00:00"}}