Security firm Socket Inc. disclosed in August 2026 that 19 Chrome and Edge extensions had been quietly delivering a shared malware framework tracked as “Superior.” Eighteen extensions targeted Chrome, one targeted Edge. Roughly 80,000 users were exposed. The campaign had been evolving since at least February 2024.
Trusted Tools, Poisoned Updates
Attackers didn’t need you to click anything suspicious — they just needed you to have already installed their extension.
Attackers either built 14 of the 19 extensions themselves — legitimate-looking utilities that worked as advertised — or bought five existing extensions from real developers and quietly poisoned them through the normal auto-update channel. Think of it like a beloved…






