← Socket Security Malicious Browser Extension Campaign August 20261 decision on this page
Audit log
Every state-changing event for Socket Security Malicious Browser Extension Campaign August 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-29 23:05:06ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
5Jbdpqn1s4K2…RuDNLZrjsha256 → base58
verifying row…canonical bytes (22000 B) ▸
{"actor":"system:backfill","investigation_id":"6088bbf8-f446-4353-956a-09ef5f824fb9","kind":"publish","page_slug":"socket-security-malicious-browser-extension-campaign-august-2026","published_at":"2026-08-29T23:05:05.978Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Socket Security Malicious Browser Extension Campaign August 2026","sections":[{"content":"Socket Security researcher Karlo Zanki disclosed on August 28, 2026 a cluster of 19 malicious browser extensions — 18 targeting Google Chrome and one targeting Microsoft Edge — that shared code architecture and infrastructure consistent with a single coordinated threat actor. Socket tracks the campaign under the internal name 'Superior', derived from naming conventions found within the malware modules themselves. The extensions collectively exposed an estimated 80,000 users to credential theft and wallet-draining risk. The most impactful single extension, 'Enable Right Click & Copy — Smart Unlock + OCR', had approximately 70,000 Chrome users and roughly 10,000 Edge users at the time the malicious code was deployed. The campaign is assessed to have roots in February 2024, making it a multi-year operation rather than an isolated incident.","heading":"Campaign Overview","severity":"critical","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"},{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"}]},{"content":"Five of the 19 extensions were not originally created by the threat actor. According to Socket's research, they were purchased from their previous owners and subsequently updated to include malicious code after accumulating legitimate user bases. The five acquired extensions are: 'Enable Right Click & Copy — Smart Unlock + OCR' (Chrome extension ID: pkoccklolohdacbfooifnpebakpbeipc), 'RapidLens - Google Lens for Screen Search' (ID: fegckejpfnlmfgkfjpinlbgmeeijjkel), 'QuickLens - Search Screen with Google Lens' (ID: kdenlnncndfnhkognokgfpabgkgehodd), 'Password Protect PDF' (ID: jamminefolhgepgihbmcjjhgldbfcikp), and 'Allow Copy - Select & Enable Right Click', an Edge extension (ID: inmkjedjdhgpknjogbjomhnbgdccckkg). Chrome's default auto-update mechanism pushed the weaponized versions to existing users without notification. The Edge version of 'Enable Right Click' received an updated command-and-control domain as recently as August 14, 2026, and was still listed as active at the time of Socket's disclosure. Socket noted that extensions with 10,000 users can be acquired for under $2,000, making the acquisition-then-weaponize model economically accessible to threat actors.","heading":"Extension Inventory: Acquired Legitimate Extensions","severity":"critical","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"QuickLens Chrome Extension Supply Chain Attack — Rescana","type":"research","url":"https://www.rescana.com/post/quicklens-chrome-extension-supply-chain-attack-cryptocurrency-theft-and-clickfix-malware-campaign-a"},{"credibility":2,"name":"QuickLens Chrome extension steals crypto, shows ClickFix attack — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/"}]},{"content":"Fourteen of the 19 extensions were built from scratch by the threat actor and disguised as SEO checkers, cryptocurrency price monitors, screen search utilities, and ad analysis tools. Confirmed crypto-themed extensions include 'LedgerLook: Wallet Checker' (Chrome ID: cngchfbfgejllcbhmeadjhiebebiome), 'DeFi Pulse Tracker' (ID: lhmcajhgadanidbopgaoobjlldegjmke), 'Blockfolio: Address Monitor' (ID: ahpnnnjbnfbhoikhohglpohnoocjcoco), and 'Multi-Chain Explorer' (ID: hfijkbdkpidafdbeebnnkhfccildbcle). The names are designed to be plausible and search-discoverable by users specifically interested in cryptocurrency portfolio management, which Socket notes increases the probability that victims already hold digital assets. Additional actor-created extensions masqueraded as productivity tools, ad-spying platforms, and VPN services.","heading":"Extension Inventory: Threat-Actor-Created Extensions","severity":"critical","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"},{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"}]},{"content":"Socket's analysis identified 16 distinct JavaScript modules embedded across the extensions. The attack chain begins with Content Security Policy (CSP) header stripping via the declarativeNetRequest permission and a rules.json configuration, disabling browser-level security protections on all pages the victim visits. Content scripts then inject hidden DOM elements containing malicious payloads as event handlers, executed in the page's main world context and immediately removed to evade inspection. Each extension establishes a persistent WebSocket connection to an attacker-controlled command-and-control server with five-minute heartbeat intervals and silently suppressed error logging. The C2 connection uses dynamic endpoint rotation, allowing the threat actor to distribute victims across multiple infrastructure nodes and customize exfiltration per target. Encrypted JavaScript modules are received from the C2 server and executed dynamically within the context of whatever site the victim is browsing. This architecture allows the threat actor to deliver new payloads or update attack logic without publishing a new extension version.","heading":"Technical Attack Methods","severity":"critical","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"Chrome Extension Hijacked to Push ClickFix Malware — eSecurity Planet","type":"news_article","url":"https://www.esecurityplanet.com/threats/chrome-extension-hijacked-to-push-clickfix-malware/"}]},{"content":"The malicious payload set includes three primary financial attack modules. The multi-chain wallet drainer targets EVM-compatible wallets (Ethereum and related chains), Solana wallets, and Tron wallets. It detects when a user interacts with 'Connect Wallet' or 'Swap' buttons on decentralized finance platforms and redirects the transaction flow to attacker-controlled processes, silently manipulating the transaction before execution. The hardware wallet seed-phrase harvester executes a full-page DOM takeover when a user visits trezor.io or ledger.com, replacing the legitimate interface with pixel-accurate phishing pages — including fake restoration and firmware update wizards — designed to capture 12-, 18-, or 24-word recovery phrases. The exchange account harvester collects authenticated session tokens and account credentials from Binance, Coinbase, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask. A fourth module functions as a universal credential grabber, hooking all password and email input events across any site visited and batching the data for exfiltration at timed intervals.","heading":"Cryptocurrency and Wallet Targeting","severity":"critical","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/crypto-exchanges/19-malicious-browser-extensions-hit-80000-crypto-users-across-chrome-and-edge-288344"}]},{"content":"Beyond cryptocurrency targeting, the extensions include modules for social media account compromise (Facebook access token theft and LinkedIn anti-CSRF bypass), full browser history exfiltration for user profiling, and ClickFix-style attack delivery. The ClickFix component presents fake browser update notifications, then manipulates the victim's clipboard to insert OS-specific commands and instructs the user to execute them, enabling malware deployment outside the browser entirely. Socket notes this expands the threat actor's capability from passive credential collection to active host compromise.","heading":"Additional Malware Capabilities","severity":"high","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":1,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"}]},{"content":"Socket documented the following command-and-control and exfiltration domains as part of the campaign's infrastructure: active-enable-right-click[.]top, api[.]enable-right-click[.]click, enable-right-click[.]click, payload[.]siteinsight[.]bond, password-protect-pdf[.]com, and cryptoratesfiatconverter[.]pro, among over 20 additional endpoints. Data exfiltration was routed through Cloudflare Workers instances identified as pipi[.]saghirmohamed19[.]workers[.]dev and mimi[.]saghirmohamed19[.]workers[.]dev. Wallet drainer payloads were hosted on cookie-whitelist[.]top and whale-alert[.]art. The phishing lure infrastructure included ggle-analytics[.]com, a domain visually mimicking Google Analytics to host pixel-accurate phishing pages. The .top TLD prevalence and Cloudflare Workers usage are assessed by Socket as tradecraft markers consistent across the full campaign.","heading":"Attacker Infrastructure","severity":"high","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"}]},{"content":"The threat actor behind this campaign has not been publicly identified by name. Socket assesses that the operation's sophistication, two-year documented duration, and modular malware architecture indicate a 'very capable threat actor.' Earlier corroborating research was published by DomainTools Investigations (May 2025), Annex Security, and monxresearch-sec, identifying overlapping infrastructure and code patterns consistent with the same operator. DomainTools' prior reporting documented over 100 fake websites and dual-function Chrome extensions from the same actor dating to at least February 2024, and noted that phishing infrastructure overlaps with cyber intrusion actors, describing the threat actor as going beyond abusive advertising. No government agency or law enforcement body had publicly attributed the campaign or announced action against the operator as of the date of Socket's disclosure.","heading":"Attribution and Campaign History","severity":"high","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"},{"credibility":2,"name":"DomainTools Investigations — Hidden Threats of Dual-Function Malware Found in Chrome Extensions","type":"research","url":"https://dti.domaintools.com/dual-function-malware-chrome-extensions/"},{"credibility":1,"name":"100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials — The Hacker News (May 2025)","type":"news_article","url":"https://thehackernews.com/2025/05/100-fake-chrome-extensions-found.html"}]},{"content":"At the time of Socket's August 28, 2026 disclosure, the Chrome versions of the identified extensions had been removed from the Chrome Web Store following Socket's report. However, Socket explicitly noted that the Edge version of the 'Allow Copy — Enable Right Click' extension remained active in the Microsoft Edge Add-ons store. Socket stated it had reported the Edge extension to Microsoft. The Chrome version of the Enable Right Click extension had already been delisted from the Chrome Web Store, but the Edge counterpart received an updated C2 domain as recently as August 14, 2026 — two weeks before public disclosure — indicating the threat actor was actively maintaining the campaign. No public statement from Google or Microsoft confirming the scope of removals had been issued as of the disclosure date.","heading":"Platform Response and Removal Status","severity":"high","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":1,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"}]},{"content":"The Superior campaign is part of a documented pattern of browser extension supply-chain attacks targeting cryptocurrency users. A separate December 2025 incident involving Trust Wallet's Chrome extension drained approximately $8.5 million from roughly 2,520 wallet addresses via a compromised extension update (v2.68) pushed through a leaked Chrome Web Store API key. CryptoSlate reporting drawing on Chainalysis data estimated $713 million in crypto losses attributable to browser and wallet extension compromises in 2025 alone, representing over 20% of that year's total exploit losses. The acquisition-then-weaponize model employed in the Superior campaign — exploiting Chrome's silent auto-update mechanism — has been identified by multiple security researchers as a structural vulnerability in the browser extension ecosystem that platform policies have not yet fully addressed.","heading":"Broader Context: Browser Extension Supply-Chain Risk","severity":"high","sources":[{"credibility":1,"name":"Trust Wallet Chrome Extension Hack Drains $8.5M via Supply Chain Attack — The Hacker News","type":"news_article","url":"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html"},{"credibility":2,"name":"How browser extensions expose crypto to a fatal design flaw — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/how-browser-extensions-expose-your-crypto-to-a-fatal-design-flaw-that-the-industry-ignored-bleeding-713m-in-2025/"}]},{"content":"Socket's disclosure includes the following mitigation recommendations for affected or at-risk users: immediately review all installed browser extensions and remove any that are unused or unrecognized; be particularly cautious of extensions whose ownership has changed or that have received unusual permission updates; avoid entering seed phrases or recovery words into any browser-based interface, including pages that appear to be from Ledger or Trezor; treat any unexpected browser update prompt that asks you to run a command as a compromise indicator. Users who had any of the named extensions installed should consider their seed phrases, exchange credentials, and social media sessions as potentially compromised and rotate them accordingly. Institutions should evaluate endpoint detection tools capable of flagging suspicious WebSocket communications initiated by browser extensions.","heading":"User Protective Measures","severity":"medium","sources":[{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"}]}],"sources_used":[{"credibility":1,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"},{"credibility":1,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/crypto-exchanges/19-malicious-browser-extensions-hit-80000-crypto-users-across-chrome-and-edge-288344"},{"credibility":2,"name":"QuickLens Chrome Extension Supply Chain Attack — Rescana","type":"research","url":"https://www.rescana.com/post/quicklens-chrome-extension-supply-chain-attack-cryptocurrency-theft-and-clickfix-malware-campaign-a"},{"credibility":2,"name":"QuickLens Chrome extension steals crypto, shows ClickFix attack — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/"},{"credibility":2,"name":"Chrome Extension Hijacked to Push ClickFix Malware — eSecurity Planet","type":"news_article","url":"https://www.esecurityplanet.com/threats/chrome-extension-hijacked-to-push-clickfix-malware/"},{"credibility":2,"name":"DomainTools Investigations — Hidden Threats of Dual-Function Malware Found in Chrome Extensions","type":"research","url":"https://dti.domaintools.com/dual-function-malware-chrome-extensions/"},{"credibility":1,"name":"100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials — The Hacker News","type":"news_article","url":"https://thehackernews.com/2025/05/100-fake-chrome-extensions-found.html"},{"credibility":1,"name":"Trust Wallet Chrome Extension Hack Drains $8.5M — The Hacker News","type":"news_article","url":"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html"},{"credibility":2,"name":"How browser extensions expose crypto to a fatal design flaw, bleeding $713M in 2025 — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/how-browser-extensions-expose-your-crypto-to-a-fatal-design-flaw-that-the-industry-ignored-bleeding-713m-in-2025/"},{"credibility":1,"name":"Chrome Extension Turns Malicious After Ownership Transfer — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html"},{"credibility":2,"name":"Chrome Extensions Caught Stealing Crypto Wallets — U.Today","type":"news_article","url":"https://u.today/chrome-extensions-caught-stealing-crypto-wallets"}],"summary":"On August 28, 2026, cybersecurity firm Socket published research identifying 19 malicious Chrome and Edge browser extensions, collectively tracked under the internal campaign name 'Superior', that embedded multi-chain wallet draining, hardware-wallet seed-phrase harvesting, and exchange credential-stealing code affecting an estimated 80,000 users. Five of the extensions were previously legitimate tools acquired from their original developers and subsequently weaponized; 14 were built from scratch by the threat actors under crypto-themed names. The campaign is assessed to have been active since at least February 2024 and remained ongoing at the time of disclosure.","timeline":[{"date":"2024-02-01","event":"Campaign origins assessed by DomainTools and Socket. Threat actor begins creating fake websites and malicious Chrome extensions under the Superior campaign infrastructure.","source":"DomainTools Investigations / Socket Security","source_url":"https://dti.domaintools.com/dual-function-malware-chrome-extensions/"},{"date":"2025-05-01","event":"DomainTools Investigations publishes research documenting over 100 fake websites and dual-function Chrome extensions from the same operator, noting infrastructure overlaps with cyber intrusion actors.","source":"The Hacker News","source_url":"https://thehackernews.com/2025/05/100-fake-chrome-extensions-found.html"},{"date":"2026-02-01","event":"Threat actors acquire QuickLens Chrome extension from its original developer and push a weaponized update embedding wallet-draining and ClickFix malware code.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/"},{"date":"2026-08-14","event":"Edge version of the compromised 'Allow Copy — Enable Right Click' extension receives an updated command-and-control domain, indicating the threat actor is actively maintaining the campaign two weeks before public disclosure.","source":"Socket Security","source_url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"date":"2026-08-28","event":"Socket Security researcher Karlo Zanki publicly discloses the full Superior campaign: 19 malicious Chrome and Edge extensions, 80,000 estimated affected users, with full technical analysis of 16 malware modules, C2 infrastructure, and extension IDs. Chrome Web Store removes identified Chrome extensions; Edge version remains active at time of publication.","source":"The Hacker News / Socket Security","source_url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision b2821271-45bd-47e9-b88d-a5b8cf2d5d3a
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.