Cybersecurity researchers have uncovered a sophisticated operation targeting browser users through nineteen malicious extensions across Google Chrome and Microsoft Edge. Known as Superior, the campaign involves eighteen Chrome additions and one Edge extension designed specifically to steal cryptocurrency wallet secrets and drain digital assets. According to Karlo Zanki of Socket, these attacks likely began as early as February 2024, utilizing a deceptive strategy where attackers either create new tools or buy existing, reputable extensions from their original developers.

The danger lies in how these extensions evolve. Many started as clean, functional tools that gained thousands of unsuspecting downloads before the attackers pushed an update containing hidden malware. Because browsers automatically update extensions by default, users who had trusted a tool for months suddenly found themselves hosting malicious code without warning. One particularly damaging extension called Enable Right Click and Copy reached an estimated 80,000 users across both platforms, providing the attackers with a massive pool of potential victims.

Once installed, the software acts as a gateway for various theft modules. Researchers identified sixteen different types of payloads including hardware wallet seed phrase harvesters and credential grabbers for social media accounts like Facebook and LinkedIn. Some versions even used a tactic known as ClickFix, which tricks users into pasting malicious commands into their own systems via fake browser update notifications. This allows the hackers to maintain deep persistence on a victim’s machine while rotating their control servers to avoid detection by security firms.

While the identity of those behind the campaign remains a mystery, experts say the longevity and technical precision of the operation point toward a very capable threat actor. By blending in with legitimate productivity tools and SEO analyzers, the group managed to bypass standard caution markers for several years. Security professionals now warn users to be extremely wary of third party extensions, emphasizing that even a once safe tool can become a weapon after a single silent update.