40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
40 malicious Firefox extensions were discovered masquerading as legitimate Web3 products (OKX, Rabby Wallet, TronLink) to steal cryptocurrency wallet secrets The campaign, dubbed "Offside Wallet Theft Factory," has been active since March 2026 and involves 77 browser add-ons sharing source code and infrastructure Attack methods include remotely loading fake wallet pages, baking stealing functionality into extensions, exfiltrating recovery phrases and private keys through Cloudflare Workers, and
Analysis
TL;DR
- 40 malicious Firefox extensions were discovered masquerading as legitimate Web3 products (OKX, Rabby Wallet, TronLink) to steal cryptocurrency wallet secrets
- The campaign, dubbed "Offside Wallet Theft Factory," has been active since March 2026 and involves 77 browser add-ons sharing source code and infrastructure
- Attack methods include remotely loading fake wallet pages, baking stealing functionality into extensions, exfiltrating recovery phrases and private keys through Cloudflare Workers, and using Supabase as remote command-and-control switches
- 37 additional extensions form a coordinated sports score-shell operation, with nine confirmed malicious identities repurposing from sports shells to wallet-stealing malware under the same Firefox IDs
- The threat actor exploits favorable economics: a single successful installation can expose wallet secrets worth far more than the cost of repeatedly publishing disposable, short-lived extensions
Why It Matters
This campaign highlights the growing sophistication of browser extension-based attacks targeting the cryptocurrency ecosystem, demonstrating how threat actors exploit the Firefox Add-ons marketplace as a low-cost, high-reward distribution channel. The use of legitimate cloud infrastructure (Supabase, Cloudflare Workers) and the strategy of repurposing existing extension identities under the same Firefox IDs reveal an evolving playbook that challenges traditional security monitoring approaches.
Technical Details
- Attack Infrastructure: Seven extensions use threat actor-controlled Supabase projects as remote switches to dynamically serve phishing or decoy content; 15 extensions capture recovery phrases, private keys, and wallet secrets, exfiltrating them through Cloudflare Workers; 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption; five extensions use hard-coded C2 infrastructure for credential and clipboard capture
- Extension Repurposing Strategy: Nine confirmed malicious identities initially appeared as sports score or utility shells (football, basketball, NBA, hockey) before being repurposed into wallet-stealing malware under the same Firefox IDs, maintaining user trust through established extension histories
- Deceptive Functionality: The 37 sports score-shell extensions share hard-coded credentials for legitimate API-Sports while marketing unrelated functions including password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking
- Code and Identity Overlap: All 77 extensions share source code and infrastructure overlaps, with threat actors rotating names and IDs, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure to make detection and takedown efforts less effective
- Visual Spoofing Techniques: Some malicious extensions use character substitution in names (e.g., ℞ab␢y Wa❘Iet, Rabb-Walӏet) to impersonate legitimate wallets like Rabby Wallet while evading automated detection systems
Industry Insight
- Marketplace Security Gaps: The Firefox Add-ons ecosystem remains a viable attack surface due to the low cost of publishing disposable extensions and the ability to repurpose existing identities, suggesting a need for enhanced behavioral monitoring and reputation-based detection beyond static code analysis
- Cloud Infrastructure Exploitation: The use of legitimate services like Supabase and Cloudflare Workers as C2 infrastructure demonstrates how threat actors leverage trusted cloud platforms to blend in with legitimate traffic, highlighting the importance of monitoring for anomalous usage patterns rather than blocking specific domains
- Web3 Security Awareness: The campaign's focus on cryptocurrency wallets underscores the high-value target nature of Web3 products, urging users and developers to implement stricter extension verification practices, such as checking publisher reputations, reviewing extension permissions, and using hardware wallets for significant holdings
Disclaimer: The above content is generated by AI and is for reference only.