Microsoft, Google, Trezor and Facebook: Malicious Chrome and Edge Extensions Hijack Crypto Wallets and Steal Login Credentials

Microsoft, Google, Trezor and Facebook: Malicious Chrome and Edge Extensions Hijack Crypto Wallets and Steal Login Credentials

Malicious Browser Extensions Target Crypto Wallets in "Superior" Campaign

Researchers have uncovered 19 malicious browser extensions 18 for Google Chrome and one for Microsoft Edge linked to a coordinated campaign dubbed Superior. The activity, first reported by DomainTools in February 2024 and later analyzed by Secure Annex, exploits trust in seemingly legitimate browser tools, including SEO trackers, crypto-price monitors, and screen-search utilities.

The extensions initially functioned as advertised, but after gaining traction, attackers pushed updates containing hidden malicious code. Of the 19 extensions, 14 were created by the threat actors, while five were acquired from legitimate developers. The most widely distributed was "Enable Right Click & Copy Smart Unlock + OCR," originally developed by PreppHint before being hijacked. At the time of the malicious update, it had approximately 70,000 Chrome users and 10,000 Edge users, though not all installations received the rogue version.

Google removed the malicious Chrome extension from its Web Store, but the Edge version remained active, with attackers updating its command-and-control (C2) infrastructure on August 14, 2026. The malware establishes a persistent WebSocket connection to its C2 server, generating unique victim identifiers and receiving encrypted JavaScript modules. To evade detection, it rotates C2 endpoints and uses separate exfiltration servers for each victim.

A critical technique involves stripping Content Security Policy (CSP) headers from websites, allowing the extension to inject malicious scripts. These payloads target Ethereum-compatible, Solana, and Tron wallets, hijacking "Connect Wallet" or "Swap" buttons to trick users into approving fraudulent transactions. Additional modules impersonate Ledger and Trezor recovery pages, stealing seed phrases to gain full wallet control.

Beyond cryptocurrency theft, the campaign targets users of major exchanges including Coinbase, Binance, Kraken, and MetaMask stealing session cookies, authorization tokens, and account details. A universal form-grabbing module captures text inputs, passwords, and browser history, while separate modules compromise Facebook tokens and LinkedIn sessions. The attack underscores the risks of compromised browser extensions, particularly those with automatic update mechanisms.

Source: https://cyberpress.org/rogue-extensions-steal-wallets/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security-response-center

Google TPRM report: https://www.rankiteo.com/company/google-chrome

Trezor TPRM report: https://www.rankiteo.com/company/trezor

Facebook TPRM report: https://www.rankiteo.com/company/meta

"id": "goomictremet1788168069",
"linkid": "google-chrome, microsoft-security-response-center, trezor, meta",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '70,000 Chrome users, 10,000 '
                                              'Edge users (estimated)',
                        'industry': 'Software (Browser Extensions)',
                        'name': 'PreppHint',
                        'type': 'Browser Extension Developer'},
                       {'industry': 'FinTech',
                        'name': 'Coinbase',
                        'size': 'Large',
                        'type': 'Cryptocurrency Exchange'},
                       {'industry': 'FinTech',
                        'name': 'Binance',
                        'size': 'Large',
                        'type': 'Cryptocurrency Exchange'},
                       {'industry': 'FinTech',
                        'name': 'Kraken',
                        'size': 'Large',
                        'type': 'Cryptocurrency Exchange'},
                       {'industry': 'FinTech',
                        'name': 'MetaMask',
                        'size': 'Large',
                        'type': 'Cryptocurrency Wallet'},
                       {'industry': 'FinTech',
                        'name': 'Ledger',
                        'size': 'Large',
                        'type': 'Hardware Wallet Provider'},
                       {'industry': 'FinTech',
                        'name': 'Trezor',
                        'size': 'Large',
                        'type': 'Hardware Wallet Provider'},
                       {'industry': 'Technology',
                        'name': 'Facebook',
                        'size': 'Large',
                        'type': 'Social Media Platform'},
                       {'industry': 'Technology',
                        'name': 'LinkedIn',
                        'size': 'Large',
                        'type': 'Professional Networking Platform'}],
 'attack_vector': 'Malicious Browser Extensions',
 'data_breach': {'data_encryption': 'No (data exfiltrated in plaintext or '
                                    'encrypted via C2)',
                 'data_exfiltration': 'Yes (via WebSocket to C2 servers)',
                 'personally_identifiable_information': 'Yes (seed phrases, '
                                                        'passwords, browser '
                                                        'history, session '
                                                        'tokens)',
                 'sensitivity_of_data': 'High (PII, financial credentials, '
                                        'authentication tokens)',
                 'type_of_data_compromised': ['Cryptocurrency wallet '
                                              'credentials',
                                              'Seed phrases',
                                              'Session cookies',
                                              'Authorization tokens',
                                              'Passwords',
                                              'Browser history',
                                              'Facebook tokens',
                                              'LinkedIn sessions',
                                              'Exchange account details']},
 'date_detected': '2024-02',
 'date_publicly_disclosed': '2024-02',
 'description': 'Researchers uncovered 19 malicious browser extensions (18 for '
                'Google Chrome and one for Microsoft Edge) linked to a '
                'coordinated campaign dubbed *Superior*. The extensions '
                'initially functioned as advertised but later received updates '
                'containing hidden malicious code. The campaign targets '
                'cryptocurrency wallets, exchanges, and user credentials by '
                'injecting malicious scripts, stripping CSP headers, and '
                'stealing seed phrases, session cookies, and authorization '
                'tokens.',
 'impact': {'brand_reputation_impact': 'Risk of reputational damage for '
                                       'affected exchanges (Coinbase, Binance, '
                                       'Kraken, MetaMask) and wallet providers '
                                       '(Ledger, Trezor)',
            'data_compromised': 'Cryptocurrency wallet credentials, seed '
                                'phrases, session cookies, authorization '
                                'tokens, passwords, browser history, Facebook '
                                'tokens, LinkedIn sessions, exchange account '
                                'details',
            'identity_theft_risk': 'High (seed phrases, PII, and credentials '
                                   'stolen)',
            'operational_impact': 'Unauthorized access to cryptocurrency '
                                  'wallets and exchange accounts, potential '
                                  'loss of funds',
            'payment_information_risk': 'High (cryptocurrency wallet and '
                                        'exchange account compromise)',
            'systems_affected': 'User devices with infected browser extensions '
                                '(Chrome, Edge)'},
 'initial_access_broker': {'backdoors_established': 'Persistent WebSocket '
                                                    'connection to C2 server',
                           'entry_point': 'Malicious browser extensions',
                           'high_value_targets': ['Cryptocurrency wallets '
                                                  '(Ethereum, Solana, Tron)',
                                                  'Crypto exchanges (Coinbase, '
                                                  'Binance, Kraken)',
                                                  'MetaMask users',
                                                  'Facebook/LinkedIn '
                                                  'sessions']},
 'investigation_status': 'Ongoing (Edge version still active as of August 14, '
                         '2026)',
 'lessons_learned': 'The incident highlights the risks of malicious browser '
                    'extensions, particularly those with automatic update '
                    'mechanisms. Users should verify extension developers, '
                    'disable automatic updates for sensitive tools, and '
                    'monitor extension behavior. Organizations should enforce '
                    'CSP headers and educate users on phishing risks related '
                    'to wallet connections.',
 'motivation': 'Financial Gain (Cryptocurrency Theft, Credential Harvesting)',
 'post_incident_analysis': {'corrective_actions': ['Remove malicious '
                                                   'extensions from official '
                                                   'stores (Google Web Store, '
                                                   'Microsoft Edge Add-ons).',
                                                   'Rotate compromised '
                                                   'credentials and tokens.',
                                                   'Implement stricter review '
                                                   'processes for extension '
                                                   'updates.',
                                                   'Enhance monitoring of '
                                                   'extension behavior and '
                                                   'network activity.'],
                            'root_causes': ['Exploitation of automatic update '
                                            'mechanisms in browser extensions',
                                            'Lack of CSP enforcement on '
                                            'targeted websites',
                                            'User trust in seemingly '
                                            'legitimate extensions',
                                            'Delayed detection and removal of '
                                            'malicious extensions']},
 'recommendations': ['Disable automatic updates for browser extensions '
                     'handling sensitive data.',
                     'Verify extension developers and reviews before '
                     'installation.',
                     'Use hardware wallets for cryptocurrency storage where '
                     'possible.',
                     'Monitor browser extensions for unusual network activity.',
                     'Enforce CSP headers on websites to prevent script '
                     'injection.',
                     'Educate users on recognizing phishing attempts targeting '
                     'wallet connections.'],
 'references': [{'date_accessed': '2024-02', 'source': 'DomainTools'},
                {'source': 'Secure Annex'}],
 'response': {'containment_measures': 'Google removed malicious Chrome '
                                      'extensions from Web Store',
              'third_party_assistance': 'DomainTools, Secure Annex'},
 'threat_actor': 'Unknown (Coordinated Campaign)',
 'title': 'Superior Campaign: Malicious Browser Extensions Target Crypto '
          'Wallets',
 'type': 'Malware Distribution',
 'vulnerability_exploited': 'Automatic update mechanisms in browser '
                            'extensions, lack of CSP enforcement'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.