Tendvane

← All articles

SecurityAugust 29, 2026

The extension you installed two years ago is not the one running today

Browser extensions update themselves quietly, without asking. That single fact is the whole story here.

Researchers at Socket published findings on 28 August covering 19 add-ons, 18 for Chrome and one for Edge, tracked as a campaign they call "Superior" and traced back to February 2024. Fourteen were built by the attacker. The other five were bought from the people who wrote them, which is the part worth sitting with: someone made a useful little tool, got tired of maintaining it, sold it on, and the buyer shipped an update that did something else entirely. The largest was "Enable Right Click and Copy", with roughly 70,000 users on Chrome and another 10,000 on Edge.

The updated versions were not subtle about their ambitions. They drained crypto wallets across several blockchains, threw up fake Ledger and Trezor recovery pages to capture seed phrases, stole logged-in sessions for exchanges including Coinbase, Binance and Kraken, grabbed anything typed into a password or email box on any site, exfiltrated browsing history and Facebook and LinkedIn session tokens, and showed fake browser-update prompts that ask you to paste a command into Windows yourself. Google pulled the Chrome listing. When Socket published, the Edge version was still available.

Almost everyone is carrying extensions they stopped using years ago and have not thought about since. That is the exposure, and clearing it out takes two minutes: open your browser's extensions page and remove anything you cannot explain in a sentence. Tendvane's Safety check shows browser extensions next to startup programs, which tends to be the moment people find out what has been riding along.

Sources

Download Tendvane