Socket Details 16-Module Framework Behind Chrome and Edge Extension Campaign
Summary
The software supply-chain security firm Socket published research in late August 2026 detailing a 16-module framework used to build malicious Chrome and Edge browser extensions as part of a campaign it tracks as "Superior". The framework provides the attackers with a set of interchangeable components covering wallet draining, seed-phrase phishing and theft of active sessions on cryptocurrency exchanges.
Details
Extensions built from the framework present themselves as legitimate tools โ wallets, trading utilities, or productivity helpers โ and are distributed through official browser stores and side-loading. Once installed, the malicious modules can read or redirect browser activity, prompt for wallet seed phrases under false pretences, and steal session tokens that allow the operators to take over logged-in exchange accounts and drain balances. The modular design means the same framework can be repackaged quickly into many different extension personas, making takedown-and-resubmit cycles cheap for the operators.
Assessment
The research illustrates how the browser-extension supply chain has become a preferred delivery mechanism for crypto-focused theft: extensions sit inside the trusted browser boundary and often request permissions that look reasonable to users. Users should treat browser extensions as software with real access, review requested permissions, remove extensions they no longer use, and avoid extensions that ask for seed phrases or private keys under any circumstances. No Australian-specific targeting has been reported.