40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
ID: 22ff1875-d36a-540c-8bd0-7b934f33c80a
STIX ID: report--22ff1875-d36a-540c-8bd0-7b934f33c80a
Feed Name: The Hacker News
**Offside Wallet Theft Factory:** A coordinated campaign of malicious Firefox extensions (40 confirmed, 77 related) has been active since March 2026, impersonating Web3 wallets (OKX, Rabby, TronLink, etc.) to capture and exfiltrate recovery phrases, private keys, credentials, and clipboard data via techniques including remote fake wallet pages, baked-in stealing functionality, Supabase-based remote switches, Cloudflare Workers exfiltration, and hard-coded C2; multiple extensions first appeared as benign sports-score or utility shells before being repurposed into wallet-stealing malware and several malicious extension identities and publishing artifacts were reused or rotated to persist on the Firefox Add-ons ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
