Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Browser Extensions with Malicious Code Target Crypto Wallets

Browser Extensions with Malicious Code Target Crypto Wallets

Posted on August 28, 2026 By CWS

In a recent cyber threat revelation, researchers have identified a total of 19 browser extensions—18 for Google Chrome and one for Microsoft Edge—that are equipped with harmful code designed to steal cryptocurrency wallet secrets. These extensions, uncovered by Karlo Zanki from Socket Security, have been gradually released over the past six months, hinting at a potentially long-running operation.

Identifying the Threat

The extensions in question share similar code characteristics and methods, suggesting a coordinated campaign possibly active since February 2024. Socket Security has cataloged this activity under the moniker “Superior.” The strategy employed by these cybercriminals involves either taking over legitimate extensions or releasing initially clean versions that later evolve to maliciously compromise users’ data.

Among the 19 extensions, 14 were directly created by the cyber actors, while five were acquired from previous developers. Notably, some of these extensions had previously been flagged for malicious activities, such as “QuickLens – Search Screen with Google Lens,” which had been identified earlier this year for malware distribution and data harvesting.

Technical Insights and Impact

A detailed analysis reveals that these extensions often perform dual functions—they appear to serve their intended purpose while also connecting to malicious servers. This duality allows the extensions to transmit user data, execute arbitrary commands, and maintain persistent connections with command-and-control (C2) servers.

The extension “Enable Right Click & Copy — Smart Unlock + OCR” poses a significant risk, with an installation base spanning 80,000 users across Chrome and Edge. Each extension can communicate with C2 servers and dynamically adapt its behavior based on received instructions, facilitating targeted data exfiltration and reducing detection likelihood.

Broader Implications and Future Outlook

The malicious extensions employ sophisticated techniques, such as stripping Content Security Policy headers and injecting JavaScript modules across web pages. A total of 16 modules were identified, encompassing a range of malicious activities from wallet draining to credential theft.

The identity of the perpetrators remains a mystery, though their sustained success over two years highlights their proficiency. The most significant risk stems from their strategy of acquiring legitimate extensions and infusing them with harmful capabilities, exploiting the auto-update feature of browsers to maximize reach and impact.

In conclusion, the exposure of these malicious extensions underscores the importance of vigilance in cybersecurity, especially for users dealing with cryptocurrency. As the threat landscape evolves, staying informed and cautious about the extensions installed on browsers is crucial to protecting sensitive information.

The Hacker News Tags:browser security, C2 servers, Chrome extensions, crypto theft, crypto wallets, cyber threats, Cybersecurity, data exfiltration, Edge extensions, JavaScript injection, malicious extensions, online security, Socket security, supply chain attacks, web security

Post navigation

Previous Post: WordPress Security Breach Deploys Amatera Stealer
Next Post: Cybersecurity Roundup: Log4j Concerns, Minimus Closure

Related Posts

U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust The Hacker News
FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering FBI Warns of Scattered Spider’s Expanding Attacks on Airlines Using Social Engineering The Hacker News
CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms The Hacker News
Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets The Hacker News
BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & More BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & More The Hacker News
Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas Meta Disrupts Influence Ops Targeting Romania, Azerbaijan, and Taiwan with Fake Personas The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Hackers Exploit New Malware to Target European Entities
  • APT28’s HOOKEDGE Backdoor Targets European Entities
  • Cybersecurity Roundup: Log4j Concerns, Minimus Closure
  • Browser Extensions with Malicious Code Target Crypto Wallets
  • WordPress Security Breach Deploys Amatera Stealer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Hackers Exploit New Malware to Target European Entities
  • APT28’s HOOKEDGE Backdoor Targets European Entities
  • Cybersecurity Roundup: Log4j Concerns, Minimus Closure
  • Browser Extensions with Malicious Code Target Crypto Wallets
  • WordPress Security Breach Deploys Amatera Stealer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark