Superior malicious extension installation campaign
Campaign
Summary
Hide ▲
Show ▼
The Superior campaign is using fake websites and clean-to-malicious extension updates to push wallet-stealing browser extensions, creating a broad risk for Chrome Web Store users. The operation has been active since February 2024 and reached at least 19 extensions across Google Chrome and Microsoft Edge, including one with an 80,000-user install base.
Related Happenings
Silent Swap browser-extension clipboard clipper
Malware Activity
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
About this happening:
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
Silent Swap browser-extension clipboard clipper
Malware ActivityAbout this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...
StegoAd malicious Edge extension operation
Malware Activity
H score19
First: 29.06.2026 11:32
Last: 29.06.2026 11:32
Sources 1
About this happening:
The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
StegoAd malicious Edge extension operation
Malware ActivityAbout this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
GlassWorm OpenVSX sleeper extension campaign
Campaign
H score45
First: 28.04.2026 00:41
Last: 28.04.2026 00:41
Sources 1
About this happening:
The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
GlassWorm OpenVSX sleeper extension campaign
CampaignAbout this happening: The GlassWorm operation has launched a new wave against OpenVSX, seeding 73 sleeper extensions that become malicious after an update and can deliver malware to...
GlassWorm v2 cloned VS Code extension loaders
Malware Activity
H score30
First: 27.04.2026 14:23
Last: 27.04.2026 14:23
Sources 1
About this happening:
The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
GlassWorm v2 cloned VS Code extension loaders
Malware ActivityAbout this happening: The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...
Timeline
-
28.08.2026 18:27 2 articles · 2h ago
Superior-linked Chrome and Edge extensions steal wallet secrets and drain cryptocurrency
Campaign Scope UpdateSuperior-linked browser extensions abused legitimate-looking add-ons for wallet secret theft and cryptocurrency draining. The cluster spans 19 Google Chrome and Microsoft Edge extensions, including Enable Right Click & Copy — Smart Unlock + OCR and QuickLens - Search Screen with Google Lens, and the malicious code can connect to malicious servers, send user data, receive commands, execute arbitrary code, strip Content Security Policy headers, and keep a persistent WebSocket connection. The activity may have been active since February 2024, and the most exposed extension had an 80,000-user install base.
Show sources
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — thehackernews.com — 28.08.2026 18:27
- 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code — thehackernews.com — 28.08.2026 18:27