
Socket researchers have uncovered a network of 77 Firefox extensions tied to cryptocurrency wallet theft, credential harvesting, and deceptive software distribution.
Of those, 40 were confirmed malicious, while another 37 disguised sports-score applications as unrelated browser utilities and appear connected to the same broader publishing operation.
Socket’s Threat Research team linked the extensions through shared source code, infrastructure, Firefox add-on ID patterns, reused publishing artifacts, deceptive descriptions, and version histories showing previously innocuous extensions later being converted into wallet stealers.
Socket says the activity dates back to at least March 2026 and continued through August. Mozilla signing records for the first 59 versions analyzed ranged from March 9 to August 3, with clusters of activity in April and late July. Further investigation brought the total number of linked extension identities to 77.
Mozilla operates Firefox Add-ons, the official marketplace for browser extensions used by Firefox users worldwide. Socket reported extensions that remained available during its investigation to Mozilla’s security team, and Mozilla removed at least some of the identified add-ons before Socket published its findings.
Of the 40 confirmed malicious extensions, seven impersonated cryptocurrency products while functioning primarily as remotely controlled phishing loaders. One example, “0KX WEB3,” used a zero instead of the letter O to resemble OKX and queried a threat actor-controlled Supabase database for a URL to load inside its popup.
Attackers can change that Supabase value remotely, allowing the signed extension to display a harmless notepad when inactive and later switch to a Cloudflare Pages-hosted wallet interface. The fake page asked users to import wallets by providing recovery phrases or private keys.

Socket
Another 15 extensions embed wallet-theft code directly and send stolen secrets to attacker-controlled Cloudflare Workers. Several contained modified Rabby Wallet code, including malicious logic that intercepted 12- or 24-word recovery phrases during wallet creation or import.
Socket also found 13 Rabby-derived extensions that modified persistAllKeyrings(). Instead of attacking encrypted wallet storage, the malicious code transmitted serialized keyring information to hardcoded servers before Rabby’s normal local encryption occurred.
Five additional extensions targeted credentials and clipboard contents. They communicated with a hardcoded command-and-control address, sending captured credentials to app.php and splitting clipboard contents into numbered chunks delivered through continue.php.

Socket
The remaining 37 extensions advertised features such as VPN access, password generation, dark mode, screenshots, currency conversion, and note-taking, but actually displayed football, basketball, NBA, or hockey scores using API-Sports. Socket found no wallet or credential theft in the analyzed versions, but historical evidence showed nine malicious extension identities had previously distributed similar sports-score shells before later updates introduced wallet-stealing code.
Users who installed one of the malicious wallet extensions should assume any recovery phrase, private key, or wallet state exposed to it has been compromised. Uninstalling the extension alone is insufficient, and affected cryptocurrency funds should be moved to a newly created wallet with fresh keys. Users should also change potentially exposed passwords, revoke active sessions where possible, and review browser extension activity after updates.







Leave a Reply