Breaking
Cyber CrimeDeveloping Story

Malicious Firefox Add-ons Target Web3 Wallets

Researchers found 40 malicious Firefox extensions impersonating Web3 products to steal wallet secrets.

··3 hours ago·3 min read
teal LED panel
Photo by Adi Goldstein on Unsplash

Uncovering the Offside Wallet Theft Factory

Security researchers at Socket Threat Research have identified a coordinated campaign involving 77 Firefox browser extensions, of which 40 are confirmed as malicious. Dubbed the “Offside Wallet Theft Factory,” the operation has been active since March 2026 and is designed to steal cryptocurrency wallet secrets by impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. The group behind the campaign remains unidentified.

According to Socket's analysis, the extensions are linked through shared source code and infrastructure, and they have been engineered to trick users into revealing sensitive wallet information. The campaign shows a sophisticated approach to evading detection by repurposing extensions and embedding malicious functionality in various ways.

How the Malicious Extensions Operate

The 40 confirmed malicious extensions deploy a range of techniques to steal wallet secrets. Seven of them use threat actor-controlled Supabase projects to remotely switch between server phishing pages and decoy content, allowing them to adapt their attack in real time. Another 15 are designed to capture recovery phrases and private keys, exfiltrating the data through Cloudflare Workers.

Additionally, 13 extensions are modified builds of the legitimate Rabby Wallet extension, which exfiltrate serialized keyrings before local encryption occurs. The remaining five extensions capture credentials and clipboard data through hard-coded command-and-control infrastructure.

The wallet secrets are harvested through two primary methods: either remotely loading a fake wallet page that mimics the legitimate service, or by baking the theft functionality directly into the extension itself. In some cases, extensions initially appeared on the official Firefox Add-ons marketplace as innocuous tools, only to be later repurposed into wallet-stealing malware under the same Firefox ID.

Sports Score Shells as a Disguise

Among the broader set of 77 extensions, 37 are linked to a coordinated sports score operation that serves as a shell, containing deceptive implementations for football, basketball, NBA, and hockey. These extensions share a hard-coded credential for a legitimate service called API-Sports, which provides real-time sports data. They also market unrelated functions such as password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking, making it harder for users to spot their true intent.

According to Socket, “Historical versions of nine confirmed malicious identities also used sports-score shells spanning football, basketball, NBA, and American football before later versions under the same Firefox IDs were repurposed into wallet-stealing extensions.”

“The other 31 confirmed malicious identities lack the sports API integration but contain confirmed malicious wallet- or credential-stealing functionality,” the researchers added.

Examples of Malicious Extensions

Socket identified several malicious extensions by name, including:

  • Safe-Themes - Browser Extension (bliss-heaven@webbrol.com)
  • Rabbit For Desktop (bright-save-feed@tabtools.org)
  • ℞ab␢y Wa❘Iet (flex-clock-dash@extrakits.com)
  • Rabb-Walӏet CryptoPortfolio (free-note-bolt@webtools.co)
  • RABB-Walӏet Web3 & EVM (safe-stat-pure@proaddons.net)
  • Rabbit/WALLET - EVM (sharp-stat-gear@netplugs.net)

These extensions have been observed in the Firefox Add-ons marketplace, and users are advised to check their installed add-ons for any suspicious entries.

The Economics of Malicious Browser Extensions

Security researcher Kirill Boychenko highlighted the financial incentive behind the campaign. He explained that a single successful installation can yield a recovery phrase or private key worth far more than the cost of repeatedly publishing disposable extensions. This economic reality drives the persistence of such attacks, as attackers can easily rotate names, repurpose identities, and clone code to stay active.

“A single successful installation can expose a recovery phrase, private key, or wallet state worth far more than the cost of repeatedly publishing disposable extensions.”

— Kirill Boychenko, Security Researcher at Socket

Boychenko added that the ability to rotate names and IDs, repurpose existing extension identities, and separate malicious functionality across extensions, remote pages, and cloud infrastructure makes repeated publication cheap and scalable.

Why This Matters for Firefox Users

This campaign underscores the importance of exercising caution when installing browser extensions, especially those claiming to offer Web3 or cryptocurrency services. Since attackers are able to repurpose legitimate-looking extensions, users may unknowingly install malware that compromises their digital assets.

The fact that some extensions initially appeared as sports score or utility shells before turning malicious highlights the need for continuous vigilance and regular review of installed add-ons. Users should also be wary of extensions that request excessive permissions or ask for sensitive data such as private keys or recovery phrases.

This discovery suggests that malicious actors are increasingly targeting browser-based cryptocurrency users, potentially signaling a broader trend. It may be prudent to verify the legitimacy of any extension before installation and to monitor for any suspicious activity in your cryptocurrency wallets.

#firefox#malware#cryptocurrency#wallet theft#web3#browser security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories