19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads
Socket Threat Research team identified 19 malicious browser extensions (18 Chrome, 1 Edge) published in the last six months, delivering an extendable malware framework. These extensions establish WebSocket communication with command and control servers, strip Content Security Policy headers, and use XSS injection to execute malicious payloads. The primary focus is cryptocurrency wallet secret stealing and crypto draining. The threat actor employs two publishing approaches: creating malicious extensions from scratch or acquiring legitimate extensions with established user bases and weaponizing them. The most impactful case involves the 'Enable Right Click & Copy' extension, which had approximately 70,000 Chrome users and 10,000 Edge users when compromised. The campaign, tracked as 'Superior', has been active since February 2024, demonstrating sophisticated operational capabilities and persistent evolution of malicious modules targeting multiple cryptocurrency platforms, exchanges, and credential harvesting.
Indicators of Compromise
- domain: chrome.storage
- domain: cookie-whitelist.com
- domain: whale-alert.life
- domain: api.extensionanalyticspro.top
- url: http://api.active-enable-right-click.top/?uuid=
- url: http://ggle-analytics.com/
- domain: blockfolioaddressmonitor.pro
- domain: cookie-whitelist.top
- domain: cryptopricebadgequickglance.pro
- domain: cryptoratesfiatconverter.pro
- domain: defipulsetracker.pro
- domain: enable-right-click.click
- domain: ggle-analytics.co
- domain: ggle-analytics.com
- domain: lucky-random.sbs
- domain: password-protect-pdf.com
- domain: pricealarmsvolatilitywarnings.pro
- domain: privatecryptonewsreader.pro
- domain: whale-alert.art
- domain: api.active-enable-right-click.top
- domain: api.codefilearc.net
- domain: api.creativelibrary.top
- domain: api.enable-right-click.click
- domain: content.resonanceweb.top
- domain: e.runtime.id
- domain: extension.io-safe.icu
- domain: feedback.feedx-ray.top
- domain: payload.siteinsight.bond
- domain: relay.seopulsepro.sbs
- domain: ws.seopulsepro.sbs
- domain: ws.site-signal.top
19 Chrome and Edge Extensions Deliver a Wallet Drainer and Credential-Stealing Payloads
Description
Socket Threat Research team identified 19 malicious browser extensions (18 Chrome, 1 Edge) published in the last six months, delivering an extendable malware framework. These extensions establish WebSocket communication with command and control servers, strip Content Security Policy headers, and use XSS injection to execute malicious payloads. The primary focus is cryptocurrency wallet secret stealing and crypto draining. The threat actor employs two publishing approaches: creating malicious extensions from scratch or acquiring legitimate extensions with established user bases and weaponizing them. The most impactful case involves the 'Enable Right Click & Copy' extension, which had approximately 70,000 Chrome users and 10,000 Edge users when compromised. The campaign, tracked as 'Superior', has been active since February 2024, demonstrating sophisticated operational capabilities and persistent evolution of malicious modules targeting multiple cryptocurrency platforms, exchanges, and credential harvesting.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socket.dev/blog/chrome-edge-extension-wallet-drainer"]
- Adversary
- null
- Pulse Id
- 6a90b73a174ed7192aa841e4
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainchrome.storage | — | |
domaincookie-whitelist.com | — | |
domainwhale-alert.life | — | |
domainapi.extensionanalyticspro.top | — | |
domainblockfolioaddressmonitor.pro | — | |
domaincookie-whitelist.top | — | |
domaincryptopricebadgequickglance.pro | — | |
domaincryptoratesfiatconverter.pro | — | |
domaindefipulsetracker.pro | — | |
domainenable-right-click.click | — | |
domainggle-analytics.co | — | |
domainggle-analytics.com | — | |
domainlucky-random.sbs | — | |
domainpassword-protect-pdf.com | — | |
domainpricealarmsvolatilitywarnings.pro | — | |
domainprivatecryptonewsreader.pro | — | |
domainwhale-alert.art | — | |
domainapi.active-enable-right-click.top | — | |
domainapi.codefilearc.net | — | |
domainapi.creativelibrary.top | — | |
domainapi.enable-right-click.click | — | |
domaincontent.resonanceweb.top | — | |
domaine.runtime.id | — | |
domainextension.io-safe.icu | — | |
domainfeedback.feedx-ray.top | — | |
domainpayload.siteinsight.bond | — | |
domainrelay.seopulsepro.sbs | — | |
domainws.seopulsepro.sbs | — | |
domainws.site-signal.top | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://api.active-enable-right-click.top/?uuid= | — | |
urlhttp://ggle-analytics.com/ | — |
Threat ID: 6a914c4eacd9273b49a4e3b2
Added to database: 08/28/2026, 08:52:30 UTC
Last updated: 08/29/2026, 02:55:00 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.