Socket Security Malicious Browser Extension Campaign August 2026
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
On August 28, 2026, cybersecurity firm Socket published research identifying 19 malicious Chrome and Edge browser extensions, collectively tracked under the internal campaign name 'Superior', that embedded multi-chain wallet draining, hardware-wallet seed-phrase harvesting, and exchange credential-stealing code affecting an estimated 80,000 users. Five of the extensions were previously legitimate tools acquired from their original developers and subsequently weaponized; 14 were built from scratch by the threat actors under crypto-themed names. The campaign is assessed to have been active since at least February 2024 and remained ongoing at the time of disclosure.
Connected Entities
2 entities · 10 linked investigations- inmkjedjdhgpknjogbjomhnbgdccckkg→mentioned with→Socket Security Malicious Browser Extension Campaign August 2026(50%)
Timeline(5 events)
1 February 2024
Campaign origins assessed by DomainTools and Socket. Threat actor begins creating fake websites and malicious Chrome extensions under the Superior campaign infrastructure.
DomainTools Investigations / Socket Security1 May 2025
DomainTools Investigations publishes research documenting over 100 fake websites and dual-function Chrome extensions from the same operator, noting infrastructure overlaps with cyber intrusion actors.
The Hacker News1 February 2026
Threat actors acquire QuickLens Chrome extension from its original developer and push a weaponized update embedding wallet-draining and ClickFix malware code.
BleepingComputer14 August 2026
Edge version of the compromised 'Allow Copy — Enable Right Click' extension receives an updated command-and-control domain, indicating the threat actor is actively maintaining the campaign two weeks before public disclosure.
Socket Security28 August 2026
Socket Security researcher Karlo Zanki publicly discloses the full Superior campaign: 19 malicious Chrome and Edge extensions, 80,000 estimated affected users, with full technical analysis of 16 malware modules, C2 infrastructure, and extension IDs. Chrome Web Store removes identified Chrome extensions; Edge version remains active at time of publication.
The Hacker News / Socket SecurityDecision Log
- #1publish⛓ pending8/29/2026, 11:05:06 PMhash: 5Jbdpqn1s4K22DNzA41mJC9tddLxqHf8CkDXRuDNLZrj
0 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/29/2026, 11:04:58 PM
last updated: 8/29/2026, 11:05:06 PM
avoid.net — verified advice for a post-truth world