40 Fake Firefox Extensions Found Stealing Cryptocurrency Wallet Data
Researchers at Socket Threat Research have uncovered a large-scale malicious browser extension campaign targeting Firefox users. The campaign, dubbed the 'Offside Wallet Theft Factory,' involves 40 extensions disguised as legitimate cryptocurrency wallet tools such as OKX, Rabby Wallet, and TronLink. These fake extensions are designed to steal wallet secrets, potentially giving attackers direct access to victims' cryptocurrency funds.
The malicious extensions form part of a wider network of 77 browser add-ons that share code and infrastructure, suggesting a coordinated and well-resourced operation rather than isolated scams. By impersonating trusted Web3 brands, the attackers exploit users' familiarity with popular wallet platforms to lower their guard and encourage installation.
For small businesses that use or accept cryptocurrency payments, or whose staff manage digital assets, this campaign is a reminder that browser extensions can be a significant attack vector. Even extensions that appear legitimate or are found through browser stores should be treated with caution, especially those requesting access to sensitive financial or wallet data.