HackMyIP
← Back to News
2026-08-20 The Hacker News

40 Malicious Firefox Extensions Steal Crypto Wallets as Web3 Fakes

MalwarePhishingThreat Intel

Security researchers at Socket's Threat Research team have uncovered a sprawling campaign of 40 malicious Mozilla Firefox extensions designed to steal cryptocurrency wallet credentials by impersonating popular Web3 products, including OKX, Rabby Wallet, and TronLink. Dubbed the "Offside Wallet Theft Factory," the operation has been active since at least March 2026 and forms part of a broader cluster of 77 browser add-ons sharing overlapping source code and infrastructure. The campaign has not yet been attributed to any known threat actor or group.

Technical analysis from researcher Kirill Boychenko reveals distinct functionality across the 40 confirmed malicious extensions. Seven rely on threat actor-controlled Supabase projects acting as remote kill switches to dynamically serve phishing pages or decoy content. Another 15 capture recovery phrases and private keys, exfiltrating them through Cloudflare Workers. Thirteen modified Rabby Wallet builds harvest serialized keyrings before local encryption can occur, while the remaining five siphon credentials and clipboard data via hard-coded command-and-control endpoints. Two primary theft methods were identified: remotely loading a counterfeit wallet page or embedding the theft logic directly into the extension code itself.

The campaign's infrastructure is notably deceptive. Several add-ons first appeared on the official Firefox marketplace as innocuous sports score or utility tools, spanning football, basketball, NBA, and hockey themes, before being repurposed under the same Firefox ID into wallet-stealing malware. The 37 sibling extensions form a coordinated multi-sport shell operation that share a hard-coded credential for API-Sports, a legitimate real-time sports data provider, while marketing unrelated features such as VPN access, screenshot capture, and password generation. Confirmed malicious identities include "Safe-Themes," "Rabbit For Desktop," "Rabb-Walӏet CryptoPortfolio," and several others using homoglyph characters to mimic legitimate wallet names. Users concerned about extension-driven threats should run a browser fingerprint test to surface anomalies in their environment.

For users who may have installed any of the listed extensions, immediate action is critical. Remove the extensions, audit transaction history, and rotate any exposed wallet credentials. To check whether browser-stored passwords have already been compromised, verify them against known exposures with our password checker. Crypto holders should also run a DNS leak test to confirm traffic isn't being routed through attacker-controlled resolvers, and consider migrating wallet secrets to a hardware device isolated from browser environments entirely.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →