Skip to main content
Sign in

Socket Security Malicious Browser Extension Campaign August 2026

avoid.net/socket-security-malicious-browser-extension-campaign-august-20262/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

On August 28, 2026, cybersecurity firm Socket published research identifying 19 malicious Chrome and Edge browser extensions, collectively tracked under the internal campaign name 'Superior', that embedded multi-chain wallet draining, hardware-wallet seed-phrase harvesting, and exchange credential-stealing code affecting an estimated 80,000 users. Five of the extensions were previously legitimate tools acquired from their original developers and subsequently weaponized; 14 were built from scratch by the threat actors under crypto-themed names. The campaign is assessed to have been active since at least February 2024 and remained ongoing at the time of disclosure.

Connected Entities

2 entities · 10 linked investigations
Wallets
inmkje…ckkg
Organizations
Socket Security Malicious Browser Extension Campaign August 2026
Relationships
  • inmkjedjdhgpknjogbjomhnbgdccckkgmentioned withSocket Security Malicious Browser Extension Campaign August 2026(50%)
Have evidence about Socket Security Malicious Browser Extension Campaign August 2026?

Timeline(5 events)

1 February 2024

Campaign origins assessed by DomainTools and Socket. Threat actor begins creating fake websites and malicious Chrome extensions under the Superior campaign infrastructure.

DomainTools Investigations / Socket Security

1 May 2025

DomainTools Investigations publishes research documenting over 100 fake websites and dual-function Chrome extensions from the same operator, noting infrastructure overlaps with cyber intrusion actors.

The Hacker News

1 February 2026

Threat actors acquire QuickLens Chrome extension from its original developer and push a weaponized update embedding wallet-draining and ClickFix malware code.

BleepingComputer

14 August 2026

Edge version of the compromised 'Allow Copy — Enable Right Click' extension receives an updated command-and-control domain, indicating the threat actor is actively maintaining the campaign two weeks before public disclosure.

Socket Security

28 August 2026

Socket Security researcher Karlo Zanki publicly discloses the full Superior campaign: 19 malicious Chrome and Edge extensions, 80,000 estimated affected users, with full technical analysis of 16 malware modules, C2 infrastructure, and extension IDs. Chrome Web Store removes identified Chrome extensions; Edge version remains active at time of publication.

The Hacker News / Socket Security
Provenance & Audit Trail

Decision Log

  • #1publish⛓ pending8/29/2026, 11:05:06 PM
    hash: 5Jbdpqn1s4K22DNzA41mJC9tddLxqHf8CkDXRuDNLZrj

0 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/29/2026, 11:04:58 PM

last updated: 8/29/2026, 11:05:06 PM

avoid.net — verified advice for a post-truth world