The Hacker News

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Discovery

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to have been active since March 2026. The activity has not been attributed to any known threat actor or group.

"Extension-level analysis confirms 40 as malicious," security researcher Kirill Boychenko said. "Another 37 form a coordinated multi-sport score-shell operation. Their analyzed builds contain no confirmed credential- or wallet-stealing payloads, but their deceptive functionality, shared publishing artifacts, and version histories indicate malicious intent."

Malicious extension breakdown

Among those 40 extensions:

  1. Seven use threat actor-controlled Supabase projects as remote switches to server phishing or decoy content dynamically.
  2. 15 capture recovery phrases, private keys, and other wallet secrets, and exfiltrate them through Cloudflare Workers.
  3. 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption.
  4. The remaining five capture credentials and clipboard data through hard-coded command and control (C2) infrastructure.

Attack methods

The wallet secrets are stolen using two methods: either remotely loading a fake wallet page or baking the functionality into the extension itself. In some cases, the add-ons first appeared on the official Firefox extensions marketplace as sports score or utility shells, before they were turned into wallet-stealing malware under the same Firefox ID.

Sports score shells

The 37 extensions related to the sports score operation contain deceptive implementations spanning football, basketball, NBA, and hockey, and share a hard-coded credential for legitimate API-Sports, a legitimate service that delivers real-time sports data, while marketing unrelated functions such as password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking.

"Historical versions of nine confirmed malicious identities also used sports-score shells spanning football, basketball, NBA, and American football before later versions under the same Firefox IDs were repurposed into wallet-stealing extensions," Socket said. "The other 31 confirmed malicious identities lack the sports API integration but contain confirmed malicious wallet- or credential-stealing functionality."

Known malicious extensions

The names of some of the malicious extensions are below:

  • Safe-Themes - Browser Extension (bl**********@webbrol.com)
  • Rabbit For Desktop (bri*************@tabtools.org)
  • β„žab␒y Wa❘Iet (fle************@extrakits.com)
  • Rabb-Walӏet CryptoPortfolio (fre***********@webtools.co)
  • RABB-Walӏet Web3 & EVM (saf***********@proaddons.net)
  • Rabbit/WALLET - EVM (sha************@netplugs.net)

Economics of persistence

"A single successful installation can expose a recovery phrase, private key, or wallet state worth far more than the cost of repeatedly publishing disposable extensions," Boychenko said. "That economics helps explain the threat actors’ persistence in targeting the Firefox Add-ons ecosystem even when individual extensions are short-lived and ultimately removed. Rotating names and IDs, repurposing existing extension identities, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure make repeated publication cheap and scalable."

Read on The Hacker News ↗ ← Back to News

Comments

No comments yet. Start the discussion.