{"id":2480,"date":"2026-08-21T02:07:02","date_gmt":"2026-08-21T02:07:02","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2480"},"modified":"2026-08-21T02:07:02","modified_gmt":"2026-08-21T02:07:02","slug":"40-malicious-firefox-extensions-pose-as-web3-products-to-steal-wallet-secrets","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2480","title":{"rendered":"40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 20, 2026<\/span><\/span><span class=\"p-tags\">Browser Security \/ Cryptocurrency<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhA5ySurVDL2oPvG7l78G22fbZEDplybrP5KX79GCEuhHybqkIgDGWDY_iHNfSLhKMt4sxn51CF33lRNwyjQy-l4Zajbkl9qUFxsjHEIoVsFhWBcGoHavMzOnmbWAI-8VHreBmZhuoCPs_N5KAKLFccr-bFLhzvJq12bvhvp5upRSkZulRN4tUDUTkfTRqo\/s1700-e365\/firefox.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.<\/p>\n<p>According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed <strong>Offside Wallet Theft Factory<\/strong>, is believed to have been active since March 2026. The activity has not been attributed to any known threat actor or group.<\/p>\n<p>\u00abExtension-level analysis confirms 40 as malicious,\u00bb security researcher Kirill Boychenko <a href=\"https:\/\/socket.dev\/blog\/firefox-crypto-wallet-theft#Counterfeit-Wallets-Collect-Secrets-Directly\" target=\"_blank\">said<\/a>. \u00abAnother 37 form a coordinated multi-sport score-shell operation. Their analyzed builds contain no confirmed credential- or wallet-stealing payloads, but their deceptive functionality, shared publishing artifacts, and version histories indicate malicious intent.\u00bb<\/p>\n<p>Among those 40 extensions, seven use threat actor-controlled Supabase projects as remote switches to server phishing or decoy content dynamically; 15 capture recovery phrases, private keys, and other wallet secrets, and exfiltrate them through Cloudflare Workers; 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption; and the remaining five capture credentials and clipboard data through hard-coded command and control (C2) infrastructure.<\/p>\n<p>The wallet secrets are stolen using two methods: either remotely loading a fake wallet page or baking the functionality into the extension itself. In some cases, the add-ons first appeared on the official Firefox extensions marketplace as sports score or utility shells, before they were turned into wallet-stealing malware under the same Firefox ID. <\/p>\n<p>The 37 extensions related to the sports score operation contain deceptive implementations spanning football, basketball, NBA, and hockey, and share a hard-coded credential for legitimate <a href=\"https:\/\/api-sports.io\/\" target=\"_blank\">API-Sports<\/a>, a legitimate service that delivers real-time sports data, while marketing unrelated functions such as password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abHistorical versions of nine confirmed malicious identities also used sports-score shells spanning football, basketball, NBA, and American football before later versions under the same Firefox IDs were repurposed into wallet-stealing extensions,\u00bb Socket said.<\/p>\n<p>\u00abThe other 31 confirmed malicious identities lack the sports API integration but contain confirmed malicious wallet- or credential-stealing functionality.\u00bb<\/p>\n<p>The names of some of the malicious extensions are below &#8211;<\/p>\n<ul>\n<li>Safe-Themes &#8211; Browser Extension (bliss-heaven@webbrol.com)<\/li>\n<li>Rabbit For Desktop (bright-save-feed@tabtools.org)<\/li>\n<li>\u211eab\u2422y Wa\u2758Iet (flex-clock-dash@extrakits.com)<\/li>\n<li>Rabb-Wal\u04cfet CryptoPortfolio (free-note-bolt@webtools.co)<\/li>\n<li>RABB-Wal\u04cfet Web3 &amp; EVM (safe-stat-pure@proaddons.net)<\/li>\n<li>Rabbit\/WALLET &#8211; EVM (sharp-stat-gear@netplugs.net)<\/li>\n<\/ul>\n<p>\u00abA single successful installation can expose a recovery phrase, private key, or wallet state worth far more than the cost of repeatedly publishing disposable extensions,\u00bb Boychenko said.<\/p>\n<p>\u00abThat economics helps explain the threat actors\u2019 persistence in targeting the Firefox Add-ons ecosystem even when individual extensions are short-lived and ultimately removed. Rotating names and IDs, repurposing existing extension identities, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure make repeated publication cheap and scalable.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 20, 2026Browser Security \/ Cryptocurrency A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2481,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[361,510,33,2150,3119,145,571,1049,3118],"class_list":["post-2480","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-extensions","tag-firefox","tag-malicious","tag-pose","tag-products","tag-secrets","tag-steal","tag-wallet","tag-web3"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2480"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2480\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2481"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}