Skip to content
Beveiligingsnieuws

Malicious Firefox Extensions Steal Wallet Secrets

Firefox-extensies walletgeheimen

Security researchers report a campaign involving malicious Firefox extensions that were designed to steal cryptocurrency wallet secrets. The extensions posed as well-known Web3 products and services, aiming to trick users into installing add-ons that ultimately harvest recovery phrases, private keys, and other sensitive wallet data.

The activity was linked by the Socket Threat Research team to an ongoing effort they call Offside Wallet Theft Factory. According to the report, the operation is believed to have been active since March 2026, and the malicious behavior is not currently attributed to a specific, named threat actor group.

What makes the campaign particularly concerning is its scale and modular design: researchers describe overlaps in code and infrastructure across multiple add-ons, along with strategies to keep the malicious operations difficult to track over time.

How the campaign targeted Firefox users

The findings describe a set of 40 Firefox add-ons confirmed as malicious, part of a larger collection of 77 browser extensions that share source code and supporting infrastructure. Rather than relying on one single payload, the researchers observed a coordinated approach where different extensions handled different stages of the theft process.

The analysis also highlights that some add-ons initially appeared in roles that look benign or unrelated—such as sports score shells, utility-like tools, or other deceptive wrappers. Later, those same extension identities were repurposed to perform wallet-stealing functions.

Researchers noted that a number of malicious identities rotated through historical versions. In several cases, extensions first served “sports score” or similar features and were then rewritten or reconfigured under the same Firefox ID to conduct credential and wallet theft.

Which wallet brands were used as disguises

To increase trust, the malicious extensions impersonated popular Web3-related products. The report specifically mentions masquerading as tools including OKX, Rabby Wallet, and TronLink, along with other Web3 services.

This kind of branding can be especially effective because many users search for familiar interfaces when managing tokens, signing transactions, or recovering access to a wallet. By blending into that expectation, the add-ons reduce suspicion and encourage installation.

What makes these malicious Firefox extensions dangerous

Once installed, the extensions targeted sensitive wallet information through multiple mechanisms. Researchers describe two broad ways the theft was executed: either by dynamically presenting a fake wallet page to the victim, or by baking the malicious capture logic directly into the extension itself.

In addition, some extensions relied on remote switching behavior—meaning they could fetch instructions or decide what to show based on server-side conditions. That allows the same extension to behave differently across targets or time periods.

Four main theft techniques described in the report

The report breaks down observed malicious capabilities across the confirmed extensions. While not every add-on used the same method, the overall pattern shows coordinated wallet-harvesting behavior.

1) Remote switches and dynamic phishing

Seven of the 40 confirmed malicious extensions used threat actor-controlled Supabase projects as remote switches. These switches were used to trigger server phishing or to deliver decoy content dynamically, changing the behavior without needing to release a brand-new extension for every variation.

2) Direct capture of recovery phrases and private keys

Another set—15 extensions—was described as capable of capturing recovery phrases, private keys, and other wallet secrets. The report states that the stolen data was exfiltrated using Cloudflare Workers, which can help conceal where data is sent and how it is processed.

3) Modified wallet builds and exfiltration of keyrings

Researchers also observed modifications of Rabby Wallet builds. Thirteen extensions were described as altering the wallet components in a way that exfiltrated serialized keyrings before any local encryption protections could be applied.

4) Credential and clipboard harvesting via hard-coded infrastructure

Finally, five extensions were described as capturing credentials and clipboard data. In these cases, the malicious behavior was tied to hard-coded command-and-control (C2) infrastructure rather than being purely dependent on remote decoy logic.

Deceptive features used to lower user suspicion

To appear legitimate, the malicious add-ons were not limited to “steal wallet data” functionality. Researchers describe deceptive features embedded in sports-score themed and utility-like builds.

For example, the sports-score related extensions were reported to include implementations spanning football, basketball, NBA, and hockey. They also reportedly included marketing for unrelated capabilities such as password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking—features that make the extension look like a general-purpose tool rather than a wallet threat.

Some of those sports-score shells were reported to share a hard-coded credential for API-Sports, a legitimate service that provides real-time sports information. The presence of a legitimate sports integration makes the add-on’s surface-level behavior more plausible, even while other functions were malicious.

Names of detected extensions

The report lists several examples of malicious extensions identified in the analysis. The specific names below illustrate how the campaign reused or rebranded identities to maintain credibility:

  • Safe-Themes – Browser Extension (bliss-heaven@webbrol.com)
  • Rabbit For Desktop (bright-save-feed@tabtools.org)
  • ℞ab␢y Wa❘Iet (flex-clock-dash@extrakits.com)
  • Rabb-Walӏet CryptoPortfolio (free-note-bolt@webtools.co)
  • RABB-Walӏet Web3 & EVM (safe-stat-pure@proaddons.net)
  • Rabbit/WALLET – EVM (sharp-stat-gear@netplugs.net)

These examples show how attackers can use character tricks, naming patterns, and “product-style” branding to blend into a noisy extension marketplace.

Why short-lived extensions can still succeed

Researchers emphasize that even if individual malicious extensions are removed after being detected, the campaign can remain profitable. One reason is the “economics” of browser extension abuse: it can be cheap and scalable to repeatedly publish disposable add-ons, rotate identities, and clone code.

Socket Threat Research describes several tactics that support persistence even when one extension version is taken down. These include rotating names and IDs, reusing existing Firefox extension identities, separating malicious functionality across multiple extensions and remote pages, and using cloud-based infrastructure to support exfiltration and dynamic behavior.

The report also points out that a single successful installation may expose a wallet recovery phrase, private key, or wallet state worth far more than the cost of publishing repeated malicious extensions.

What users can do to reduce risk

While this report focuses on an observed campaign, the broader takeaway is clear: users should treat unfamiliar or oddly branded malicious Firefox extensions as a serious threat to wallet security. If you use browser-based Web3 workflows, take extra care with installed add-ons.

  • Review installed extensions regularly and remove anything you did not intentionally install or verify.
  • Be cautious with brand imitation—even if an extension name looks like a known wallet provider, confirm the publisher and purpose.
  • Avoid entering recovery phrases or private keys into anything presented by a browser extension, especially pages that appear unexpected.
  • Watch for unusual wallet prompts or sudden redirects to pages that do not match the wallet you normally use.

If you suspect compromise, consider securing your wallet immediately and rotating credentials where appropriate. Wallet theft incidents can escalate quickly, especially when sensitive material is harvested.

Conclusion: a scalable threat to Web3 wallet security

The Socket Threat Research findings describe a coordinated campaign using malicious Firefox extensions to steal cryptocurrency wallet secrets. By impersonating well-known Web3 products, leveraging remote switching and dynamic phishing, and capturing recovery phrases and private keys through multiple exfiltration paths, the extensions present a clear and high-impact risk.

Most importantly, the report shows how attackers can keep returning even after takedowns: they rotate identities, repurpose extension IDs, clone code, and distribute malicious logic across add-ons and infrastructure. For Firefox users involved in Web3 activities, staying vigilant about which extensions are installed—and what those extensions can access—remains essential.

Source: https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html