19 Chrome and Edge Extensions Compromised for Crypto Theft

19 Chrome and Edge Extensions Compromised for Crypto Theft

First seen 28 Aug 2026, 16:50 UTC ThehackernewsFeeds.4Sysops 61.5

Article Content

Browse articles
ThreatCluster

A campaign named Superior has compromised 19 Chrome and Edge extensions, employing a modular malware framework designed to drain cryptocurrency wallets, steal credentials, and hijack browser sessions. The operation has likely been active since February 2024, leveraging acquired extensions and automatic browser updates to infiltrate established user bases without raising immediate alarms. Affected users include those utilizing these extensions for cryptocurrency transactions. The malware's capabilities include credential theft and session hijacking, posing a significant risk to users' financial assets. Current status indicates ongoing exploitation, with no immediate remediation steps provided in the articles.

Key Points: • 19 Chrome and Edge extensions are compromised by modular malware. • The malware can drain cryptocurrency wallets and steal user credentials. • The operation has likely been active since February 2024.

Timeline

2024-02-01
Campaign Superior begins
The Superior campaign likely starts, compromising multiple browser extensions.
Feeds.4Sysops
2026-08-28
News articles published
Two articles report on the compromised extensions and the associated risks to users.
Feeds.4Sysops
2026-08-28
Malware capabilities detailed
Reports confirm the malware's ability to drain wallets and hijack sessions.
Thehackernews