Forty malicious Firefox extensions have been detected stealing cryptocurrencies, impersonating popular Web3 products such as OKX , Rabby Wallet , and TronLink . According to the Socket Threat Research team , these extensions are part of a larger set of 77 browser add-ons that share common source code and infrastructure, in a coordinated operation dubbed the “Offside Wallet Theft Factory .” The campaign appears to have been active since March 2026 and has not been attributed to any known threat group.
Security researcher Kirill Boychenko of Socket confirmed that 40 extensions are proven malicious, while another 37 act as shells with deceptive functionality. While the 37 do not contain confirmed credential-stealing payloads, their common publishing artifacts, version histories, and coordinated structure suggest clear malicious intent. The operating model resembles an industrial assembly line: code reuse, identity switching, and distribution of malicious functionality across multiple layers.
This discovery comes at a time when browser extensions have emerged as one of the most dangerous attack vectors in the cybersecurity space. Unlike traditional malware, malicious browser add-ons exploit the trust users have in official marketplaces, often bypassing security mechanisms without the need to exploit a known vulnerability.
See also: Malicious extensions in the Firefox store steal crypto

How malicious Firefox extensions work
Socket ’s analysis reveals four distinct categories of malicious behavior across the 40 Firefox extensions . Seven of them use Supabase projects controlled by the attackers as remote switches, enabling the dynamic delivery of phishing content. Fifteen extensions record recovery phrases, private keys, and other wallet secrets, which they export via Cloudflare Workers . Thirteen modified versions of Rabby Wallet export serialized keyrings before local encryption, while the remaining five steal credentials and clipboard data via hardcoded C2 infrastructure.
Wallet secrets are stolen in two main ways: either by remotely loading a fake wallet page, or by embedding the stealing functionality directly into the extension. In some cases, extensions were initially listed on the official Firefox as innocent sports scores tools or utilities, before being transformed into wallet stealing tools under the same Firefox ID. This tactic allows attackers to bypass the marketplace's initial vetting, as the malicious functionality is only activated after initial approval.
The names of the malicious extensions include: Safe-Themes – Browser Extension, Rabbit For Desktop, Rabb-Walӏet CryptoPortfolio, RABB-Walӏet Web3 & EVM , and Rabbit/WALLET – EVM. It is noteworthy that many names use misleading Unicode characters to imitate well-known brands, making them difficult for users to recognize.
The 37 extensions related to the sports scores business contain deceptive implementations covering football, basketball, NBA and hockey, while sharing hardcoded credentials for the legitimate API-Sports, a service that provides real-time sports data. At the same time, they promote unrelated features such as password generation, dark mode, VPN access, currency conversion, screenshot capture and notes.
See also: Mozilla releases ad-blocker in Firefox for iOS
This campaign is not isolated. There have been a number of similar incidents in 2026 : malicious VS Code extensions called “Solidity Pro” were used to steal browser wallet data, API keys , SSH keys , and credentials. Also, in June 2026, a case was reported of “Free VPN” extensions for Firefox and Chrome that added clipboard stealing code and exported copied text every few hundredths of a second. These incidents demonstrate that browser extensions have become a recurring attack surface for stealing credentials and cryptocurrency.
How to protect yourself from malicious Firefox extensions
Organizations and individual users should treat browser extensions as a software supply chain risk. Specifically, it is recommended to maintain an allowlist of approved extensions, remove unnecessary add-ons , and regularly check extension permissions and recent version changes. Cryptocurrency management teams should isolate wallet activity to a dedicated browser or device, avoid using the same browser for general browsing and asset management, and require hardware wallets for high-value transactions.

Security teams should monitor for the presentation of fake wallet brands, check for extensions that request broad access to websites or clipboard permissions, and block or investigate any add-on that suddenly changes issuer identity, name, or functionality. If a breach is suspected, it is recommended to immediately disconnect the terminal, transfer assets to a clean wallet from a trusted device. Any seed phrase or private key that was entered into the malicious extension should be considered exposed.
See also: Mozilla Firefox: Fixes “Heap Buffer Overflow” vulnerability
According to The Hacker News, this campaign is a reminder that even official app stores do not provide an absolute guarantee of security, and that critically evaluating each extension before installation remains an irreplaceable security practice.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
