AI Security AI安全 1d ago Updated 1d ago 更新于 1天前 41

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets 40个恶意Firefox扩展伪装成Web3产品窃取钱包密钥

40 malicious Firefox extensions were discovered masquerading as legitimate Web3 products (OKX, Rabby Wallet, TronLink) to steal cryptocurrency wallet secrets The campaign, dubbed "Offside Wallet Theft Factory," has been active since March 2026 and involves 77 browser add-ons sharing source code and infrastructure Attack methods include remotely loading fake wallet pages, baking stealing functionality into extensions, exfiltrating recovery phrases and private keys through Cloudflare Workers, and 40个恶意Firefox扩展伪装成OKX、Rabby Wallet等Web3产品,窃取用户钱包恢复短语和私钥 该行动名为"Offside Wallet Theft Factory",自2026年3月起活跃,涉及77个共享源码和基础设施的浏览器插件 攻击者采用动态远程开关技术,部分扩展先以体育比分工具上架,后通过同一Firefox ID转为恶意软件 窃取的数据通过Cloudflare Workers和硬编码C2基础设施外泄,单个成功安装即可导致重大资产损失 攻击者通过轮换名称、复用扩展身份和分离恶意功能实现低成本规模化攻击

62
Hot 热度
60
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • 40 malicious Firefox extensions were discovered masquerading as legitimate Web3 products (OKX, Rabby Wallet, TronLink) to steal cryptocurrency wallet secrets
  • The campaign, dubbed "Offside Wallet Theft Factory," has been active since March 2026 and involves 77 browser add-ons sharing source code and infrastructure
  • Attack methods include remotely loading fake wallet pages, baking stealing functionality into extensions, exfiltrating recovery phrases and private keys through Cloudflare Workers, and using Supabase as remote command-and-control switches
  • 37 additional extensions form a coordinated sports score-shell operation, with nine confirmed malicious identities repurposing from sports shells to wallet-stealing malware under the same Firefox IDs
  • The threat actor exploits favorable economics: a single successful installation can expose wallet secrets worth far more than the cost of repeatedly publishing disposable, short-lived extensions

Why It Matters

This campaign highlights the growing sophistication of browser extension-based attacks targeting the cryptocurrency ecosystem, demonstrating how threat actors exploit the Firefox Add-ons marketplace as a low-cost, high-reward distribution channel. The use of legitimate cloud infrastructure (Supabase, Cloudflare Workers) and the strategy of repurposing existing extension identities under the same Firefox IDs reveal an evolving playbook that challenges traditional security monitoring approaches.

Technical Details

  • Attack Infrastructure: Seven extensions use threat actor-controlled Supabase projects as remote switches to dynamically serve phishing or decoy content; 15 extensions capture recovery phrases, private keys, and wallet secrets, exfiltrating them through Cloudflare Workers; 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption; five extensions use hard-coded C2 infrastructure for credential and clipboard capture
  • Extension Repurposing Strategy: Nine confirmed malicious identities initially appeared as sports score or utility shells (football, basketball, NBA, hockey) before being repurposed into wallet-stealing malware under the same Firefox IDs, maintaining user trust through established extension histories
  • Deceptive Functionality: The 37 sports score-shell extensions share hard-coded credentials for legitimate API-Sports while marketing unrelated functions including password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking
  • Code and Identity Overlap: All 77 extensions share source code and infrastructure overlaps, with threat actors rotating names and IDs, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure to make detection and takedown efforts less effective
  • Visual Spoofing Techniques: Some malicious extensions use character substitution in names (e.g., ℞ab␢y Wa❘Iet, Rabb-Walӏet) to impersonate legitimate wallets like Rabby Wallet while evading automated detection systems

Industry Insight

  • Marketplace Security Gaps: The Firefox Add-ons ecosystem remains a viable attack surface due to the low cost of publishing disposable extensions and the ability to repurpose existing identities, suggesting a need for enhanced behavioral monitoring and reputation-based detection beyond static code analysis
  • Cloud Infrastructure Exploitation: The use of legitimate services like Supabase and Cloudflare Workers as C2 infrastructure demonstrates how threat actors leverage trusted cloud platforms to blend in with legitimate traffic, highlighting the importance of monitoring for anomalous usage patterns rather than blocking specific domains
  • Web3 Security Awareness: The campaign's focus on cryptocurrency wallets underscores the high-value target nature of Web3 products, urging users and developers to implement stricter extension verification practices, such as checking publisher reputations, reviewing extension permissions, and using hardware wallets for significant holdings

TL;DR

  • 40个恶意Firefox扩展伪装成OKX、Rabby Wallet等Web3产品,窃取用户钱包恢复短语和私钥
  • 该行动名为"Offside Wallet Theft Factory",自2026年3月起活跃,涉及77个共享源码和基础设施的浏览器插件
  • 攻击者采用动态远程开关技术,部分扩展先以体育比分工具上架,后通过同一Firefox ID转为恶意软件
  • 窃取的数据通过Cloudflare Workers和硬编码C2基础设施外泄,单个成功安装即可导致重大资产损失
  • 攻击者通过轮换名称、复用扩展身份和分离恶意功能实现低成本规模化攻击

为什么值得看

本文揭示了Web3生态中针对浏览器扩展供应链的系统性攻击模式,展示了攻击者如何利用合法扩展商店的审核漏洞进行持久化威胁。对AI从业者而言,这体现了恶意软件即服务(MaaS)模式的演进趋势,以及云基础设施被武器化用于数据窃取的新手法。

技术解析

  • 动态远程开关架构:7个扩展使用威胁行为者控制的Supabase项目作为远程开关,可动态切换服务器钓鱼页面或诱饵内容,实现攻击功能的远程更新
  • 多通道数据外泄:15个扩展通过Cloudflare Workers窃取恢复短语和私钥;13个修改版Rabby Wallet在本地加密前外泄序列化密钥环;5个扩展使用硬编码C2基础设施捕获凭据和剪贴板数据
  • 扩展身份复用策略:9个恶意扩展先以体育比分工具上架,后通过同一Firefox ID转为钱包窃取恶意软件,利用历史版本积累的用户信任
  • 跨平台伪装技术:37个体育比分外壳扩展共享API-Sports硬编码凭据,同时营销密码生成、VPN、货币转换等无关功能,形成多用途伪装矩阵
  • 低成本规模化攻击:攻击者通过轮换名称/ID、克隆代码和分离恶意功能,实现"单次成功安装收益远超扩展发布成本"的经济模型

行业启示

  • 扩展商店审核机制需升级:Mozilla等平台应加强扩展行为监控,特别是检测动态远程配置和跨版本功能突变,建立扩展行为基线分析系统
  • Web3安全防御需供应链视角:钱包项目方应建立扩展生态安全审计标准,用户需验证扩展发布者历史版本变更,避免仅依赖名称和图标识别
  • 云基础设施滥用成为新趋势:攻击者将Supabase、Cloudflare Workers等合法云服务武器化,安全厂商需开发针对云原生恶意软件检测的AI分析工具

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究