Superior: Crypto and Credential Theft via Browser Extension Acquisition and Malicious Updates
1. Basic Information Article Title : Chrome Web Store extensions caught stealing crypto, browser data Publisher : BleepingComputer Publication Date : 2026-08-30 Source : BleepingComputer Related Source : Socket Threat Research Related Malware, Threat Groups, CVEs, and Products : Superior, Google Chrome, Microsoft Edge, Chrome Web Store, Microsoft Edge Add-ons Severity : High 2. Executive Summary…
Threat actors acquire or create Chrome and Edge browser extensions, then later release malicious updates to steal crypto wallets, credentials, session data and browsing history. These extensions first appear legitimate to build trust with users. Once installed, automatic updates push malicious code from a command and control server, stripping security protections and displaying fake update prompts.
The malicious extension uses a background service worker to download JavaScript modules encrypted with a key from the extension ID and installation UUID. It registers rules to remove Content Security Policy headers from web pages, then injects malicious code into hidden DOM elements that execute in the webpage's main context. The extension can intercept crypto transactions, steal recovery phrases, obtain user credentials, capture browsing history and execute arbitrary commands via ClickFix-style prompts.
Victims typically see no warning before the attack. Administrators should block known malicious extensions, limit unnecessary extensions in managed environments and monitor for suspicious traffic to C2 servers. Users should avoid executing prompts from unknown sources and employ EDR solutions to detect malicious browser behavior.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.