---
title: 19 Malicious Chrome and Edge Extensions Steal Wallet Data and Drain Crypto - Capstone Technologies Group
description: Socket researchers discovered 19 malicious Chrome and Edge extensions stealing cryptocurrency wallet data and drains funds. Learn about the Superior campaign…
canonical_url: https://captechgroup.com/threat-intelligence-center/19-malicious-chrome-and-edge-extensions-steal-wall-b6daca
language: en-GB
date: 2026-08-28T18:05:49Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/threat-intelligence-center/19-malicious-chrome-and-edge-extensions-steal-wall-b6daca. Schema.org structured data included at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
markdown-tokens: 5362
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/threat-intelligence-center/19-malicious-chrome-and-edge-extensions-steal-wall-b6daca. Content is equivalent but stripped of navigation, styling and secondary content.
> **Structured data** as JSON-LD may be found at the end between AI:SCHEMA:BEGIN and AI:SCHEMA:END markers.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


Socket researchers found 19 malicious browser extensions, 18 in the Chrome Web Store and one in the Microsoft Edge Add-ons store, carrying code that steals cryptocurrency wallet secrets and drains funds. All 19 were published over the past six months, but researcher Karlo Zanki traced the shared code and tradecraft back to February 2024. Socket tracks the activity under the name Superior. Original reporting for this article comes from [The Hacker News](https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html "Source: The Hacker News").

The operator built 14 of the extensions from scratch and bought the other five from their original developers. The buy-then-poison approach matters because those five already had real users and real functionality. Extensions like **QuickLens - Search Screen with Google Lens**, **Password Protect PDF**, and **RapidLens** did the job they advertised until a new version arrived carrying the malicious payload.

> The extension with the widest reach, "Enable Right Click &amp; Copy," has a combined install base of 80,000 users across Chrome and Edge.

The rest of the roster leans heavily on crypto and marketing niches: **LedgerLook: Wallet Checker**, **DeFi Pulse Tracker**, **Blockfolio: Address Monitor**, **Multi-Chain Explorer**, plus SEO traffic checkers and Facebook ad library tools aimed at marketing staff.

Once active, the code strips Content Security Policy headers from every page you visit and injects JavaScript modules through content scripts. Socket identified 16 distinct modules covering multi chain wallet draining, hardware wallet seed phrase harvesting, exchange and wallet account credential theft, a universal form grabber, Facebook and LinkedIn account stealers, browser history theft, and a **ClickFix** style lure that shows a fake browser update and walks the user through copying a malicious command.

Browser extensions are attractive to attackers for a simple reason. They run inside the authenticated browser session with permissions most people approve once and never revisit, and Chrome's default settings update them automatically. That means an extension your staff installed and vetted a year ago can turn into a credential grabber without anyone clicking anything.

## The Extension Portfolio: Crypto Trackers, SEO Checkers and Utility Tools

Eight of the nineteen extensions carry crypto branding, making wallet users the single largest targeting group in the portfolio. That is a deliberate filter. Someone who installs a wallet checker or a DeFi tracker almost certainly holds keys, seed phrases, or exchange sessions worth draining, so the operator does not have to sort valuable victims from worthless ones after infection.

The crypto-adjacent cluster:

- Blockfolio: Address Monitor (ahpnnnjbnfbhoikhohglpohnoocjcoco)
- LedgerLook: Wallet Checker (cngchfbfgejllcbhmeadjhiebebiome)
- Crypto Alerter: Price Alarms &amp; Volatility Warnings (jmlgannjlbliikgcaieomgmcnfplglea)
- Crypto Price Badge: Quick Glance (gfackggoapepdmnjnkblogdcjpgcjiak)
- Crypto Rates &amp; Fiat Converter (oeacadlaclegkkkdehjmiifnjhcekclj)
- DeFi Pulse Tracker (lhmcajhgadanidbopgaoobjlldegjmke)
- Multi-Chain Explorer (hfijkbdkpidafdbeebnnkhfccildbcle)
- Private Crypto News Reader (iekoapohahgmogbagegmcgplbkikcgke)

The injected module set matches the audience. Socket identified a multi-chain wallet drainer, a hardware-wallet seed-phrase harvester, and an exchange and wallet account harvester among the sixteen modules, which are exactly the components you would build for a victim pool selected this way.

The second cluster targets marketing and agency staff:

- SEO Pulse Pro (Website Traffic &amp; SEO Analyzer, fjmlhlkccegopebcllcmafahkmeejpph)
- Site Signal (Website Traffic &amp; SEO Checker, dkdadldmiefjldmegbjbnhhfddnkhlhm)
- Website Traffic Checker: MirrorSphere SEO Stats (aapdalkmclfaahehnmicbglkohkldhne)
- Creative Library (Ad Spy Tool, cfpnjdbpojpcongfaefcamjbaolpelcd)
- Meta &amp; Facebook Ad Library Spy / FeedX-Ray (aodkjdeghbjiaienipfjkbpcikkacbcp)
- PixelCheck (fcgdejjichpgfaaafflplhfijcnieopb)

Marketers browse with authenticated sessions to ad platforms and social accounts open all day. The module list includes Facebook and LinkedIn account stealers alongside a universal credential and form grabber, which lines up with a victim who is logged into Business Manager and a company LinkedIn page. For an agency, a compromised ad account means fraudulent spend on a corporate card and a hijacked brand presence, and the client whose campaigns run through that account inherits the problem.

The third cluster is general browser utility software, installed for convenience by users with no particular profile:

- Enable Right Click &amp; Copy (Smart Unlock + OCR, koccklolohdacbfooifnpebakpbeipc)
- Allow Copy (Select &amp; Enable Right Click, inmkjedjdhgpknjogbjomhnbgdccckkg, Microsoft Edge)
- Password Protect PDF (jamminefolhgepgihbmcjjhgldbfcikp)
- QuickLens (Search Screen with Google Lens, kdenlnncndfnhkognokgfpabgkgehodd)
- RapidLens (Google Lens for Screen Search &amp; Images, fegckejpfnlmfgkfjpinlbgmeeijjkel)

This is the volume tier. Enable Right Click &amp; Copy alone accounts for a collective install base of 80,000 users across Chrome and Edge, the largest single footprint in the set. Right-click unlockers and PDF tools get installed on work laptops by people who never think about them again, which is what makes them useful carriers for the browser history stealer and the ClickFix-style module that displays a fake browser update and walks the user through copying an operating system specific command into a terminal.

Read across the three clusters and the design becomes clear. Crypto bait supplies high-value individual victims, marketing tools supply session tokens tied to corporate ad and social infrastructure, and utilities supply reach. Any of the nineteen installed on a machine with corporate logins gives the operator a credential grabber running inside a browser your users already trust.

## How the Superior Extensions Harvest Wallet Data

The first thing the malicious code does on a page is strip **Content Security Policy headers**. CSP is the browser rule that tells a site which scripts it is allowed to run, so removing it lets the extension inject its own JavaScript into banking portals, exchange dashboards, and webmail without the page objecting. For a business, that means a site you trust to be locked down can be rewritten in the user's browser while the padlock icon still shows.

Injection happens through content scripts, the standard extension mechanism for running code inside a visited page. Socket identified **16 separate injectable modules**, pulled in selectively depending on which site the victim is visiting:

- A multi-chain wallet drainer that operates across different blockchain networks
- A hardware-wallet seed-phrase harvester, aimed at users who type a recovery phrase during device setup or restore
- A cryptocurrency exchange and wallet account harvester
- A universal credential and form grabber that captures whatever is typed into input fields
- Facebook and LinkedIn account stealers
- A browser history stealer
- A **ClickFix**-style lure module

The modular design matters operationally. The same installed extension can behave as a harmless utility for months and then receive a credential grabber the moment the operator decides the victim is worth harvesting. Corporate exposure is not limited to crypto here, because the form grabber and the social account stealers work against any login page the user visits on a managed device.

The ClickFix module injects a fake browser update prompt and serves operating-system-specific instructions telling the user to copy a command and paste it into a terminal or Run dialog. This maps to MITRE ATT&amp;CK T1204 (User Execution), and it moves the attack off the browser and onto the endpoint itself. That is the step where a browser-only problem becomes a host compromise your endpoint tooling has to catch.

Every extension in the cluster opens a persistent **WebSocket connection** to a command-and-control server, which corresponds to T1071.001 (Application Layer Protocol: Web Protocols). The loading framework accepts an instruction from the initial C2 server to rotate to a different endpoint, and Socket confirmed that behaviour in the wild. Zanki noted that the rotation "enables threat actors to distribute victims to different groups and dedicated C2 infrastructure and to reduce the detection risk."

The exfiltration destination is also handed down dynamically in C2 instructions, giving each victim a separate outbound channel. Blocking one domain does not blind the operator, and it means the network indicators from one infected machine will not necessarily match the next one on your network.

Store review was never really the obstacle. The operator submitted extensions that work exactly as advertised, waited for install counts to build, and then shipped a version carrying the malicious loader. Because Chrome auto-updates extensions by default, the poisoned build lands on every existing user without a click, a warning, or a fresh permission prompt.

Reach follows install base. **Enable Right Click &amp; Copy — Smart Unlock + OCR** (`koccklolohdacbfooifnpebakpbeipc` on Chrome, `inmkjedjdhgpknjogbjomhnbgdccckkg` for the Edge listing under the name Allow Copy) carries roughly 80,000 combined installs, the largest single population in the set. Related earlier tradecraft included fake websites impersonating productivity tools, VPN services, ad and media analysis assistants, and banking or cryptocurrency utilities to funnel users toward the Chrome Web Store listings, per DomainTools Investigations in May 2025.

## Organizations and Operational Exposure for Businesses

Cryptocurrency theft has no reversal mechanism. If a drainer moves funds out of a wallet controlled by your finance lead or a crypto-holding employee, there is no card issuer to call, no chargeback window, and no bank to freeze the transfer. The loss is final at the moment the transaction confirms.

Scale matters here. **Enable Right Click &amp; Copy — Smart Unlock + OCR** alone carries a collective install base of 80,000 users across Chrome and Edge, and it is one of five extensions the operator bought rather than built. Those users installed a working productivity tool from a legitimate developer and received the malicious version through a routine background update.

That update path is the part your endpoint policy probably never accounted for. Chrome's default settings auto-update extensions to the latest published version, so no one on your team clicked anything, approved anything, or saw a prompt. An extension that passed your review in March can be carrying a wallet drainer by June.

The exposure extends well past anyone who trades crypto. Extensions like **Creative Library - Ad Spy Tool**, **Meta &amp; Facebook Ad Library Spy | FeedX-Ray**, and the cluster of SEO and traffic checkers are marketing department tools by design. The people who install them are logged into Meta Business Manager, LinkedIn Campaign Manager, Google Analytics, and your ad billing accounts on the same browser profile.

Socket documented dedicated Facebook and LinkedIn account stealer modules in this campaign, alongside a universal credential and form grabber. In practice that means an attacker who compromises a marketing workstation can take over the ad accounts that hold your payment methods. Ad-account fraud is a well-established follow-on to this kind of access, and recovering a hijacked business page or ad account from a platform support queue takes time your campaigns do not have.

The broader problem is what any extension with broad host permissions can see. Once granted access to all sites, it reads authenticated pages and session cookies as your users browse, which covers your CRM, your webmail, your payroll portal, and your internal admin panels. Nothing in that requires stolen passwords, because the extension is already inside the authenticated session.

The **ClickFix module** pushes the risk off the browser entirely. It injects a fake browser update notice with operating-system-specific instructions and asks the user to copy and paste a command, which is a straightforward route from browser compromise to code running on the endpoint itself. At that point you are handling a host intrusion, not an extension removal.

Two facts make scoping an incident harder than usual. The campaign rotates its command-and-control endpoints on instruction and assigns exfiltration destinations per victim, so a blocklist built from one infected machine may not match the next. And because Google and Microsoft removing an extension from the store does not uninstall it from devices where it is already present, your affected endpoints stay affected until someone actively removes the extension.

Underneath all of this sits a governance gap most organisations share. You almost certainly maintain an inventory of installed applications, but few companies maintain an equivalent inventory of browser extensions on managed endpoints, including which permissions each one holds and who approved it. Without that record, you cannot answer the first question your insurer, auditor, or client will ask after this campaign: were any of these nineteen extensions running on your machines, and for how long?

## Removing the Extensions and Controlling What Employees Can Install

Start by searching your fleet for the 19 extension IDs published by Socket. On a Windows endpoint the installed extension folders sit under `%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\` and `%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Extensions\`, each one named for its extension ID, so an [EDR](https://captechgroup.com/services/cybersecurity-services "Cybersecurity Services | Protect Your Business with Capstone Technologies") file search or a simple script gives you a fleet-wide answer in minutes. Users can also confirm locally at `chrome://extensions` and `edge://extensions`, though you should not rely on self-reporting for something that auto-updated silently.

Force removal through policy rather than asking people to uninstall. Adding the IDs to `ExtensionInstallBlocklist` (Chrome) and the Edge equivalent under `HKLM\Software\Policies\Microsoft\Edge\ExtensionInstallBlocklist` removes the extension and prevents reinstallation. Verify the policy actually landed by checking `chrome://policy` and `edge://policy` on a sample of machines, because a blocklist that never applied because of a GPO scoping error looks identical to a clean fleet.

That means:

**Key Insight:** Any device that ran one of the crypto-branded extensions should be treated as compromised, not cleaned.



- Rotate passwords for exchange accounts, webmail, and any site the user logged into from that browser profile, then revoke active sessions server-side so stolen cookies stop working.
- Move funds to wallets whose seed phrases were generated on a different, known-clean device. A seed phrase typed or displayed in a browser with an injected harvester is no longer secret, and a password change does nothing to protect it.
- Review wallet and exchange transaction history for withdrawals or approvals the user did not initiate, including token spend approvals that stay valid until revoked.
- Check for commands run from the Windows Run dialog, PowerShell history, or terminal history in case the user followed a pasted "browser update" instruction.

Revoked passwords do not close the identity side of this. Harvested logins get reused later from unfamiliar locations and devices, which is what you actually detect. In environments Capstone manages, Adlumin ITDR monitors authentication patterns for those anomalous sign-ins across managed environments, so a credential stolen through a browser injection surfaces when someone tries to use it.

Once containment is done, build the inventory you did not have. Pull a full extension list per user from your endpoint tooling and sort by permissions, not by name. Extensions requesting `<all_urls>` host access, `clipboardRead`, `webRequest`, or `nativeMessaging` deserve individual review, since those permissions are what make page injection and clipboard capture possible in the first place. A screenshot tool that wants to read every site you visit is worth a question.

For the long term, move Chrome and Edge to a default-deny model. Set `ExtensionInstallBlocklist` to `*` and permit only reviewed IDs through `ExtensionInstallAllowlist`. The `ExtensionSettings` policy gives you finer control, including `blocked_permissions` to deny clipboard and native messaging access globally and `runtime_blocked_hosts` to keep any approved extension out of your banking and finance domains regardless of what its manifest requests. Enable `BlockExternalExtensions` to stop sideloaded installs that never touch a web store.

An allowlist also changes what an acquisition attack can do to you. When an approved extension ships a new version, your review pipeline is the gate, and Chrome's automatic update behaviour no longer pushes a new owner's code onto every machine that has it installed. Set a recurring review of the allowlist so ownership changes get caught rather than inherited.

## What Extension Store Removals Do and Do Not Fix

Store removal is a cleanup action, and it happens after the malicious version has already shipped. The review process on both the Chrome Web Store and the Microsoft Edge Add-ons store evaluates an extension at submission time, so an operator who publishes a clean build, collects installs, and then pushes an update carrying the drainer modules passes vetting on the version nobody was worried about.

The timeline in Socket's research makes the limit clear. QuickLens was flagged publicly by Annex Security and monxresearch-sec earlier this year, and DomainTools Investigations documented parts of the same operation in May 2025, yet the cluster kept publishing through the past six months. Individual takedowns did not end a campaign Socket traces back to February 2024.

Delisting also does nothing about what already left your environment. If an employee ran one of these extensions on a machine with wallet access, exchange sessions, or saved credentials, that data went out through a per-victim exfiltration endpoint before the listing came down. You cannot recall it, and rotating what was exposed is a separate exercise from removing the extension.

There is also no store signal for ownership change. When a developer sells an extension, the users who trusted the original author keep receiving updates from whoever now holds the account, and your fleet inherits that trust decision silently.

The action that carries the most weight is an enforced extension allowlist on managed devices, so anything not explicitly approved cannot install or update. Alongside that, confirm no machine in your estate still carries one of the 19 extension IDs Socket named.

<!-- AI:SCHEMA: Schema.org description of canonical page in JSON-LD format -->
<!-- AI:SCHEMA:BEGIN format=jsonld scope=page -->

```json
{
    "@context": "http:\/\/schema.org",
    "@graph": [
        {
            "@type": "Article",
            "author": {
                "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
            },
            "dateModified": "2026-08-28T18:05:49Z",
            "datePublished": "2026-08-28T18:05:49Z",
            "description": "Socket researchers discovered 19 malicious Chrome and Edge extensions stealing cryptocurrency wallet data and drains funds. Learn about the Superior campaign…",
            "headline": "19 Malicious Chrome and Edge Extensions Steal Wallet Data and Drain Crypto",
            "image": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "inLanguage": "en-GB",
            "mainEntityOfPage": {
                "@type": "WebPage",
                "url": "https:\/\/captechgroup.com\/threat-intelligence-center\/19-malicious-chrome-and-edge-extensions-steal-wall-b6daca"
            },
            "publisher": {
                "@id": "https:\/\/captechgroup.com\/#defaultPublisher"
            },
            "url": "https:\/\/captechgroup.com\/threat-intelligence-center\/19-malicious-chrome-and-edge-extensions-steal-wall-b6daca"
        },
        {
            "@type": "Person",
            "name": "Brian",
            "@id": "https:\/\/captechgroup.com\/#brian_0fd5dfcdbc"
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultLogo",
            "@type": "ImageObject",
            "url": "https:\/\/captechgroup.com\/images\/hotlink-ok\/logo-light.jpg",
            "width": 1300,
            "height": 300
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPublisher",
            "@type": "Organization",
            "url": "https:\/\/captechgroup.com\/",
            "logo": {
                "@id": "https:\/\/captechgroup.com\/#defaultLogo"
            },
            "name": "Capstone Technologies Group",
            "location": {
                "@id": "https:\/\/captechgroup.com\/#defaultPlace"
            }
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultPlace",
            "@type": "Place",
            "address": {
                "@id": "https:\/\/captechgroup.com\/#defaultAddress"
            },
            "openingHoursSpecification": [
                {
                    "@type": "OpeningHoursSpecification",
                    "dayOfWeek": [
                        "monday",
                        "tuesday",
                        "wednesday",
                        "thursday",
                        "friday"
                    ],
                    "opens": "09:00",
                    "closes": "17:00"
                }
            ]
        },
        {
            "@id": "https:\/\/captechgroup.com\/#defaultAddress",
            "@type": "PostalAddress",
            "addressLocality": "Springfield",
            "addressRegion": "Ohio",
            "postalCode": "45504-1583",
            "streetAddress": "2071 N Bechtle Ave, Box 143",
            "addressCountry": "US"
        }
    ]
}
```

<!-- AI:SCHEMA:END -->

