77 Malicious Firefox Extensions Steal Crypto Wallet Secrets and Credentials
ID: 7898469b-a2c6-5300-bb53-68053b62ff04
STIX ID: report--7898469b-a2c6-5300-bb53-68053b62ff04
Feed Name: securityonline.info
Socket Threat Research documents a campaign of 77 malicious or deceptive Firefox extensions impersonating Web3 wallets (e.g., OKX, Rabby, TronLink) that exfiltrate recovery phrases, private keys, keyrings, credentials, and clipboard data to attacker-controlled cloud services (Supabase, Cloudflare Workers) and HTTP C2 servers; researchers confirmed 40 malicious extensions and identified multiple theft techniques and clusters, warning users to avoid entering wallet secrets into extension popups and to install wallets only from official sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
