Blog

Superior Campaign: 19 Browser Extensions Caught Draining Crypto Wallets

Written by tortue974 - August 28, 2026

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.

The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active since February 2024. Socket is tracking the activity under the name Superior.

The modus operandi is relatively straightforward: the threat actor either acquires legitimate extensions with proper functionality or pushes a clean version that's devoid of any malware. Once the extensions begin to gather user downloads, a new version with the malicious behavior is published.

The bait-and-switch is what makes campaigns like Superior so hard to catch: the code you reviewed at install time is not the code running on your machine six weeks later. It is the same borrowed-trust problem that keeps producing supply-chain disasters, except the trusted party here lives one click away from every password, seed phrase and session you handle in your browser. It is part of why Vulpine takes the opposite bet - no browser extension, no third-party add-on surface, keys generated and kept on your device, and an account that is nothing but a token shown once and stored only as a hash.

← All articles
Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.