Firefox extensions discovered stealing cryptocurrency from user wallets via browser compromise.
Security & Exploits ·
Security researchers at Socket have identified 77 Firefox extensions operating as part of a coordinated campaign to steal cryptocurrency wallet secrets and user credentials. The operation, tracked as "Offside Wallet Theft Factory," includes 40 extensions confirmed as malicious, with 37 additional deceptive sports-score shells linked through shared code, infrastructure, and publishing patterns. The malicious extensions impersonate legitimate Web3 products including OKX, Rabby Wallet, and TronLink, using methods such as Supabase projects for remote phishing switches, Cloudflare Workers for exfiltration of recovery phrases and private keys, and hardcoded command-and-control infrastructure for credential theft.
The campaign has operated since at least March 2026 into August, with Mozilla signing records showing peak activity in April and late July. Historical analysis reveals that nine confirmed malicious extensions previously operated as sports-score shells before being repurposed into wallet-stealing variants under the same Firefox IDs, indicating a factory-like production model. Several extensions remained live on the Firefox marketplace when researchers reported their findings in mid-August.
What remains unclear is the full scope of user impact and whether Mozilla has completed removal of all identified extensions. The investigation also notes that attribution remains under investigation, with available evidence suggesting either a common publishing pipeline or closely related threat actors coordinating the operation.