securityonline.info 9/2/2026, 8:28:25 AM · external

Malicious Browser Extensions Drain Crypto Wallets

Malicious Browser Extensions Drain Crypto Wallets
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

THE content provides an alert about critical vulnerabilities in certain PaperCut NG/MF versions (CVE-2026-82078 and CVE-2026-81578). It highlights a campaign named 'Superior', which involves 19 malicious browser extensions targeting cryptocurrency users to steal funds. These extensions appear benign initially, then push malicious updates after gaining user trust. Key techniques include phishing for wallet seeds, session theft, and credential harvesting.

The campaign has exploited Chrome's features for code injection. Users are advised to regularly audit their extensions and be cautious of permissions requested after updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline