Crypto· Altcoins

Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware

In brief Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious. They impersonate OKX, Rabby Wallet and TronLink, capturing recovery phrases through fake wallet interfaces or modified versions of real wallet code.

By AI NewsroomPublished about 6 hours agoUpdated about 1 hour ago4 views
Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware

Why It Matters

This story touches on dozens, fake, firefox — topics readers are actively tracking. Review and add editorial context before publishing.

Key Facts

  • Fact 1: In brief Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious.
  • Fact 2: Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious.
  • Fact 3: Mozilla signing records place the campaign from March 9 to August 3, with several extensions still live when Socket reported them.
  • Fact 4: Socket Threat Research uncovered a 77-extension Firefox campaign: 40 steal wallet secrets and credentials.

In brief Security firm Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious. They impersonate OKX, Rabby Wallet and TronLink, capturing recovery phrases through fake wallet interfaces or modified versions of real wallet code.

Nine were published as sports-score apps before later versions replaced that function with wallet-stealing code. Firefox users have been targeted by a production line of counterfeit crypto wallet extensions, some of which spent months publishing live football scores before being quietly converted into tools for stealing recovery phrases. Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious.

(Original synthesis pending human/AI review — generated by the stub provider by selecting real sentences from the source material, not by writing new analysis or commentary.)

Original source: Decrypt

Share

Related Stories