Malicious Firefox Extensions Steal Crypto Passwords
Security experts unearthed dozens of counterfeit Firefox extensions. These malicious add-ons masqueraded as cryptocurrency wallets and standard utilities. Some programs appeared innocuous for months. Following an update, they transformed into sinister tools. They actively purloined passwords, private keys, and wallet recovery phrases.
The Offside Wallet Theft Factory
The firm Socket identified 77 interconnected Firefox extensions. Analysts confirmed malicious code within 40 of these add-ons. Another 37 functioned as deceptive sports score applications. Researchers dubbed this campaign the Offside Wallet Theft Factory. The operation has remained active since at least March 2026. This malicious activity persisted throughout August. Furthermore, several extensions remained readily available upon initial discovery.
Deceptive Wallet Interfaces
The perpetrators skillfully forged OKX, Rabby Wallet, TronLink, and other prominent services. Seven specific extensions communicated with attacker-controlled projects on the Supabase platform. They retrieved specific webpage addresses to display to the unsuspecting user. This sophisticated mechanism initially displayed a benign notepad interface. Later, attackers remotely activated a counterfeit wallet form without deploying a new extension update.
The fraudulent page prompted users to create or import a wallet. It then explicitly requested their highly sensitive recovery phrase or private key. Upon acquiring this intelligence, the attacker easily restored the wallet on a separate device. Consequently, they usurped complete control over the victim’s funds. Official OKX documentation explicitly warns users to guard their recovery phrases and private keys with absolute secrecy.
Internal Data Plunder Mechanisms
Another 15 malicious extensions concealed an insidious data-stealing mechanism. This mechanism operated directly within the installed software package itself. A subset of these programs utilized tampered Rabby Wallet code. They intercepted crucial 12 or 24-word phrases during the wallet creation or importation process. The malware transmitted this purloined data through attacker-controlled Cloudflare Workers nodes.
Furthermore, 13 counterfeit Rabby iterations systematically plundered the keystore contents. They executed this theft before the system could encrypt the data locally. Five rogue extensions diligently harvested standard user credentials and clipboard contents. This stolen information flowed directly into a singular, unified command and control server.
Uncovering the Attacker Origin
Specialists uncovered Russian-language comments within the source code of one sample. However, Socket refrains from definitively attributing this campaign to any specific nation or syndicate.
The Trojan Horse Strategy
Thirty-seven specific extensions demanded particular scrutiny from investigators. These add-ons masqueraded as password generators, theme modifiers, currency converters, and screenshot utilities. In reality, they merely displayed live scores for football, basketball, and hockey matches.
Investigators found no data theft mechanisms within these specific verified versions. Yet, attackers previously utilized nine of these exact extension identifiers for similar sports applications. Subsequently, they distributed cryptocurrency-stealing malware utilizing those identical identifiers. This calculated approach enables the initial publication of a relatively benign program. Attackers can seamlessly inject devastating malicious functions later via a standard update.
Mitigation and Safety Protocols
Mozilla enforces strict add-on policies requiring developers to describe their extension’s functions accurately. They must also detail how the software handles sensitive user data. Socket immediately relayed comprehensive intelligence regarding these malicious extensions directly to the Mozilla security team. Consequently, Mozilla promptly eradicated the counterfeit 0KX WEB3 extension from their catalog.
Simply deleting the compromised program remains insufficient for victimized users. This applies if they inputted a recovery phrase into a suspicious extension. Socket strongly recommends treating all such critical data as permanently compromised. Users must immediately transfer their funds into an entirely new wallet protected by novel keys. Users should strictly install cryptocurrency wallets using authentic links provided directly on the official developer websites. For instance, the official Rabby website meticulously enumerates all supported wallet versions.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.