← Superior Browser Extension Campaign — Wallet Drainer3 decisions on this page
Audit log
Every state-changing event for Superior Browser Extension Campaign — Wallet Drainer: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-01 23:49:32ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 443,552,197
- sig
2VuJ1PLsX91u…RPY2tqiMexplorer ↗- hash
EKfxdNoDHYPB…uUtAF6pGsha256 → base58
verifying row…full verify ↗canonical bytes (18201 B) ▸
{"actor":"system:backfill","investigation_id":"5b4fd7aa-6d72-461c-85a1-2f6ba4c78a25","kind":"publish","page_slug":"superior-browser-extension-campaign-wallet-drainer","published_at":"2026-09-01T23:49:32.873Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Superior Browser Extension Campaign — Wallet Drainer","sections":[{"content":"Socket Security researchers publicly disclosed the Superior campaign on August 27, 2026, after identifying 19 malicious browser extensions — 18 for Google Chrome and one for Microsoft Edge — operating under a shared code framework. Socket named the operation 'Superior' based on naming conventions found within the malicious JavaScript modules. The campaign's combined user exposure at the time of disclosure was approximately 80,000 users, concentrated primarily in one widely-used Chrome extension. Code and infrastructure similarities link the malicious versions to activity dating back to at least February 2024, corroborated by prior DomainTools research. The threat actor's identity has not been publicly disclosed.","heading":"Campaign Overview","severity":"critical","sources":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"},{"credibility":2,"name":"Trusted Chrome, Edge extensions weaponized in supply chain campaign — CSO Online","type":"news_article","url":"https://www.csoonline.com/article/4215792/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign.html"}]},{"content":"The threat actor employed two parallel acquisition strategies documented by Socket Security. Of the 19 extensions, 14 were created directly by the threat actor and initially published in clean form without malicious code, gradually building an organic user base before a malicious update was pushed. The remaining five were purchased outright from their legitimate original developers. The most prominent acquisition involved 'Enable Right Click & Copy — Smart Unlock + OCR,' originally developed by PreppHint and purchased before malicious functionality was introduced. Its Chrome listing had approximately 70,000 users and the corresponding Edge listing had approximately 10,000 users at the time malicious code was deployed. Other acquired extensions include RapidLens, QuickLens, Password Protect PDF, and Allow Copy — Select & Enable Right Click. This ownership-transfer tactic exploits the browser stores' automatic update mechanism, silently distributing malware payloads to existing users without any notification that the extension had changed hands.","heading":"Supply-Chain Attack Method","severity":"critical","sources":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"Nineteen Chrome and Edge extensions drain crypto wallets, and five were bought from the developers who built them — Severity Daily","type":"news_article","url":"https://severitydaily.com/socket-superior-19-chrome-edge-extensions-acquired-wallet-drainer/"},{"credibility":2,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"}]},{"content":"Socket Security identified 16 discrete malicious modules within the campaign's framework. The malware's core mechanism involves registering a dynamic declarativeNetRequest browser rule that strips Content-Security-Policy (CSP) headers from webpages, creating an XSS-injectable environment. A persistent WebSocket connection to the C2 server — maintained with 5-minute heartbeat intervals — allows the threat actor to deliver encrypted payloads on demand. Payloads are AES-GCM encrypted using SHA-256 hashes of extension IDs and install UUIDs, and the framework supports per-victim C2 endpoint routing to complicate detection. Identified capability modules include: a multi-chain wallet drainer targeting EVM, Solana, and Tron wallets that hijacks Connect and Swap buttons; pixel-perfect fake Ledger and Trezor hardware wallet recovery interfaces designed to harvest 12-, 18-, and 24-word seed phrases; authenticated session harvesters targeting Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, and MetaMask (collecting cookies, authorization tokens, and account balances); a universal credential grabber monitoring all input fields; social media session theft targeting Facebook and LinkedIn; browser history exfiltration; and ClickFix-style fake OS update lures for additional social engineering. The extensible, module-based architecture allows the threat actor to add or update payloads remotely without publishing a new extension version.","heading":"Technical Capabilities and Malware Modules","severity":"critical","sources":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets — GBHackers","type":"news_article","url":"https://gbhackers.com/chrome-and-edge-extensions/"},{"credibility":2,"name":"19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords — Cybersecurity News","type":"news_article","url":"https://cybersecuritynews.com/extensions-caught-stealing-crypto-wallets-and-passwords/"}]},{"content":"Socket Security documented more than 17 C2 nodes used by the Superior campaign. Named infrastructure includes the domains active-enable-right-click[.]top, enable-right-click[.]click, payload[.]siteinsight[.]bond, cookie-whitelist[.]top, and whale-alert[.]art, with data exfiltration routed through Cloudflare Worker endpoints at pipi[.]saghirmohamed19[.]workers[.]dev and mimi[.]saghirmohamed19[.]workers[.]dev. The campaign adapted after Chrome-side detection: a new version of the Edge extension was published on August 14, 2026 with an updated C2 domain, indicating the threat actor monitored detection events and rotated infrastructure to keep the Edge variant active. At the time Socket published its report (August 27, 2026), the Chrome extension had been removed from the Chrome Web Store while the Edge version remained active and serving malware.","heading":"Command-and-Control Infrastructure","severity":"critical","sources":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"Nineteen Chrome and Edge extensions drain crypto wallets, and five were bought from the developers who built them — Severity Daily","type":"news_article","url":"https://severitydaily.com/socket-superior-19-chrome-edge-extensions-acquired-wallet-drainer/"},{"credibility":2,"name":"19 Chrome and Edge extensions caught harvesting crypto wallet seeds — Cyber Insider","type":"news_article","url":"https://cyberinsider.com/19-chrome-and-edge-extensions-caught-harvesting-crypto-wallet-seeds/"}]},{"content":"Socket Security identified the following 19 extensions as part of the Superior campaign. Acquired from prior legitimate owners (5): Enable Right Click & Copy — Smart Unlock + OCR; RapidLens — Google Lens for Screen Search & Images; QuickLens — Search Screen with Google Lens; Password Protect PDF; Allow Copy — Select & Enable Right Click (Microsoft Edge). Created by the threat actor and initially published clean (14): PixelCheck; Creative Library — Ad Spy Tool; Website Traffic Checker: MirrorSphere SEO Stats; Site Signal — Website Traffic & SEO Checker; SEO Pulse Pro — Website Traffic & SEO Analyzer; Private Crypto News Reader; Blockfolio: Address Monitor; Crypto Rates & Fiat Converter; Crypto Alerter: Price Alarms & Volatility Warnings; DeFi Pulse Tracker; Crypto Price Badge: Quick Glance; Multi-Chain Explorer; LedgerLook: Wallet Checker; Meta & Facebook Ad Library Spy. Extensions masquerading as SEO tools, crypto price monitors, and productivity utilities were used to attract a target audience likely to hold cryptocurrency assets.","heading":"Affected Extensions","severity":"critical","sources":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"}]},{"content":"The combined user exposure across Chrome and Edge is approximately 80,000, with the bulk concentrated in 'Enable Right Click & Copy — Smart Unlock + OCR' (approximately 70,000 Chrome users and 10,000 Edge users as reported by Socket Security). Aggregate financial losses from wallet draining have not been quantified in any source as of this writing. The total number of users who actively had assets drained versus those who merely had the malicious extension installed has not been disclosed. The extensible, remotely-loaded payload model means the threat actor could have chosen to activate different modules for different user segments, and the full scope of credential theft beyond wallet draining is unknown.","heading":"User Impact and Financial Losses","severity":"high","sources":[{"credibility":3,"name":"19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/crypto-exchanges/19-malicious-browser-extensions-hit-80000-crypto-users-across-chrome-and-edge-288344"},{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"Trusted Chrome, Edge extensions weaponized in supply chain campaign — CSO Online","type":"news_article","url":"https://www.csoonline.com/article/4215792/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign.html"}]},{"content":"The threat actor behind the Superior campaign has not been publicly identified or attributed to any known group as of the Socket Security disclosure on August 27, 2026. Socket described the actor as 'a very capable threat actor' based on the two-year operational history and the sophistication of the modular malware framework. Code and infrastructure similarities link the current campaign to activity documented by DomainTools beginning in February 2024, but no government, law enforcement, or independent attribution has been published naming a specific individual, group, or nation-state. All attribution language in this entry should be read as describing the anonymous actor responsible for the extensions, not any identified party.","heading":"Threat Actor Attribution","severity":"high","sources":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":3,"name":"Superior: Crypto and Credential Theft via Browser Extension Acquisition and Malicious Updates — DEV Community","type":"community_report","url":"https://dev.to/anoymask/superior-crypto-and-credential-theft-via-browser-extension-acquisition-and-malicious-updates-1g3o"}]},{"content":"According to Socket Security's August 27, 2026 report, Google had removed the malicious Chrome extension(s) from the Chrome Web Store by the time of publication. However, the Edge version of 'Allow Copy — Select & Enable Right Click' remained active on the Microsoft Edge Add-ons store and was serving malware at time of disclosure, having been updated with a new C2 domain on August 14, 2026 after the Chrome variant was detected. The status of all 19 extensions across both stores as of September 2026 has not been independently confirmed in sources available to this investigation. Users who installed any of the listed extensions during the period of malicious operation should treat browser-stored credentials and any connected crypto wallets as potentially compromised, revoke active sessions, and rotate seed phrases where possible.","heading":"Store Response and Remediation Status","severity":"critical","sources":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"Nineteen Chrome and Edge extensions drain crypto wallets, and five were bought from the developers who built them — Severity Daily","type":"news_article","url":"https://severitydaily.com/socket-superior-19-chrome-edge-extensions-acquired-wallet-drainer/"}]}],"sources_used":[{"credibility":2,"name":"19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads — Socket Security (primary research)","type":"research","url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"credibility":2,"name":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"},{"credibility":2,"name":"Nineteen Chrome and Edge extensions drain crypto wallets, and five were bought from the developers who built them — Severity Daily","type":"news_article","url":"https://severitydaily.com/socket-superior-19-chrome-edge-extensions-acquired-wallet-drainer/"},{"credibility":2,"name":"Trusted Chrome, Edge extensions weaponized in supply chain campaign — CSO Online","type":"news_article","url":"https://www.csoonline.com/article/4215792/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign.html"},{"credibility":2,"name":"Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets — GBHackers","type":"news_article","url":"https://gbhackers.com/chrome-and-edge-extensions/"},{"credibility":2,"name":"19 Chrome and Edge extensions caught harvesting crypto wallet seeds — Cyber Insider","type":"news_article","url":"https://cyberinsider.com/19-chrome-and-edge-extensions-caught-harvesting-crypto-wallet-seeds/"},{"credibility":2,"name":"19 Chrome and Edge Extensions Caught Stealing Crypto Wallets and Passwords — Cybersecurity News","type":"news_article","url":"https://cybersecuritynews.com/extensions-caught-stealing-crypto-wallets-and-passwords/"},{"credibility":3,"name":"19 Malicious Browser Extensions Hit 80,000 Crypto Users Across Chrome and Edge — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/crypto-exchanges/19-malicious-browser-extensions-hit-80000-crypto-users-across-chrome-and-edge-288344"},{"credibility":3,"name":"Superior: Crypto and Credential Theft via Browser Extension Acquisition and Malicious Updates — DEV Community","type":"community_report","url":"https://dev.to/anoymask/superior-crypto-and-credential-theft-via-browser-extension-acquisition-and-malicious-updates-1g3o"},{"credibility":2,"name":"Malicious Chrome and Edge Extensions Hijack Crypto Wallets and Steal Login Credentials — Cyberpress","type":"news_article","url":"https://cyberpress.org/rogue-extensions-steal-wallets/"}],"summary":"The 'Superior' campaign is a coordinated browser extension supply-chain attack identified by Socket Security in August 2026. Nineteen malicious Chrome and Edge extensions — collectively reaching approximately 80,000 users — deliver a multi-module malware framework capable of draining EVM, Solana, and Tron wallets, harvesting hardware-wallet seed phrases, and stealing credentials from major exchanges. The threat actor remains unidentified but has operated since at least February 2024, with confirmed infrastructure updates as recently as August 14, 2026.","timeline":[{"date":"2024-02","event":"Earliest infrastructure and code activity linked to the Superior campaign identified, based on similarities to activity documented by DomainTools.","source":"Socket Security / CSO Online","source_url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"date":"2026-02","event":"Approximate start of the six-month window in which the 19 malicious extension versions were published, per Socket Security's timeline.","source":"Socket Security","source_url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"date":"2026-08-14","event":"After Chrome extension detected and removal initiated, threat actor publishes updated Edge extension version with a new C2 domain, confirming the campaign is actively adapting.","source":"Socket Security","source_url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"date":"2026-08-27","event":"Socket Security publishes full public disclosure of the Superior campaign, naming 19 extensions, 16 malware modules, and associated C2 infrastructure. Chrome version reported as removed; Edge version reported as still live.","source":"Socket Security","source_url":"https://socket.dev/blog/chrome-edge-extension-wallet-drainer"},{"date":"2026-08-27","event":"Coverage of the disclosure published by The Hacker News, Bleeping Computer, CSO Online, Cybersecurity News, GBHackers, Cyber Insider, and others.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision c67b6c4a-e845-4857-b048-f9c8e4784d1e - #2reviewby reviewerreviewer2026-09-02 00:36:45ZScore: 0 → 0 (no score change)The page's claims are extensively and independently corroborated by the Socket Security primary research post and at least six independent secondary outlets, including verbatim confirmation of highly specific technical details (declarativeNetRequest CSP stripping, AES-GCM/SHA-256 key derivation, named C2 domains, and Cloudflare Worker endpoints). The only softness found was in the completeness of the 14-item 'created clean' extension name list, where several names could only be indirectly corroborated via matching C2 domain-naming patterns rather than direct secondary-source confirmation of every individual name. No contradictions, stale claims, or dead links were found among the sources checked, though one lower-tier source (cyberpress.org) could not be rendered by the fetch tool despite being confirmed to exist and match the page's claims via search-index content.anchoranchored
- chain
- ●mainnet-betaslot 443,561,252
- sig
3C8CEQxAB7eJ…s1Do6qTyexplorer ↗- hash
EsibPPB773eS…f4ExKGxUsha256 → base58
verifying row…full verify ↗canonical bytes (1334 B) ▸
{"actor":"reviewer","artifact_identity":"69cd18d6fc7a4248c829da7a484208a1","decided_at":"2026-09-02T00:36:45.243Z","decision":"review","disputed_pct":0,"investigation_id":"5b4fd7aa-6d72-461c-85a1-2f6ba4c78a25","new_score":0,"page_slug":"superior-browser-extension-campaign-wallet-drainer","prev_score":0,"reason":"The page's claims are extensively and independently corroborated by the Socket Security primary research post and at least six independent secondary outlets, including verbatim confirmation of highly specific technical details (declarativeNetRequest CSP stripping, AES-GCM/SHA-256 key derivation, named C2 domains, and Cloudflare Worker endpoints). The only softness found was in the completeness of the 14-item 'created clean' extension name list, where several names could only be indirectly corroborated via matching C2 domain-naming patterns rather than direct secondary-source confirmation of every individual name. No contradictions, stale claims, or dead links were found among the sources checked, though one lower-tier source (cyberpress.org) could not be rendered by the fetch tool despite being confirmed to exist and match the page's claims via search-index content.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 2a4ad0a3-97a6-4a27-9f24-0d6d93e56f4f - #3review approveby judgejudge2026-09-02 00:36:45ZScore: 0 → 0 (no score change)Every core claim on this page checked out. All 15 fact-checked claims were rated confirmed or partially_supported by the reviewer, with 0% disputed, stale, or dead-link findings (summary.disputed_pct = 0.0). The central allegations — the 19-extension supply-chain campaign, the acquisition-vs-clean-build tactic, the malware's technical mechanics, and the named C2 infrastructure — are each independently corroborated by the Socket Security primary research post plus multiple independent secondary outlets (claim_findings[0], [4], [5], [7]). The only softness is in claim_findings[9], where a handful of the 14 'created clean' extension names could only be matched indirectly via C2 domain-naming patterns rather than a direct secondary-source confirmation of every single name — a completeness nuance, not an inaccuracy. The reviewer also flagged a high-priority coverage gap (no on-chain fund-flow tracing of drained wallets), but this is an opportunity for expansion rather than a defect in what the page currently asserts, consistent with the principle that open coverage gaps do not by themselves warrant denial or revision when nothing on the page is actually disputed.anchoranchored
- chain
- ●mainnet-betaslot 443,561,269
- sig
2buZY5QZDXdK…G2tdgwifexplorer ↗- hash
mZPVpWGvqHrZ…kFMQbTEXsha256 → base58
verifying row…full verify ↗canonical bytes (1683 B) ▸
{"actor":"judge","artifact_identity":"69cd18d6fc7a4248c829da7a484208a1","band_override":null,"decided_at":"2026-09-02T00:36:45.243Z","decision":"review_approve","delist_requested":false,"disputed_pct":0,"investigation_id":"5b4fd7aa-6d72-461c-85a1-2f6ba4c78a25","new_score":0,"page_slug":"superior-browser-extension-campaign-wallet-drainer","prev_score":0,"reason":"Every core claim on this page checked out. All 15 fact-checked claims were rated confirmed or partially_supported by the reviewer, with 0% disputed, stale, or dead-link findings (summary.disputed_pct = 0.0). The central allegations — the 19-extension supply-chain campaign, the acquisition-vs-clean-build tactic, the malware's technical mechanics, and the named C2 infrastructure — are each independently corroborated by the Socket Security primary research post plus multiple independent secondary outlets (claim_findings[0], [4], [5], [7]). The only softness is in claim_findings[9], where a handful of the 14 'created clean' extension names could only be matched indirectly via C2 domain-naming patterns rather than a direct secondary-source confirmation of every single name — a completeness nuance, not an inaccuracy. The reviewer also flagged a high-priority coverage gap (no on-chain fund-flow tracing of drained wallets), but this is an opportunity for expansion rather than a defect in what the page currently asserts, consistent with the principle that open coverage gaps do not by themselves warrant denial or revision when nothing on the page is actually disputed.","score_delta":0,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 1e4008c7-66e0-4124-af4f-e15156fe9476
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.