Key facts
- Security firm Socket identified 77 Firefox extension identities linked to crypto-stealing malware.
- Forty of these extensions were confirmed as malicious, impersonating popular crypto wallets.
- Some extensions began as sports score apps before being updated with wallet-stealing code.
- The malware aimed to capture users' recovery phrases and private keys.
- The campaign was active between March 9 and August 3.
Dozens of counterfeit cryptocurrency wallet extensions have been discovered on Firefox, designed to steal users' sensitive recovery phrases and credentials. Security firm Socket linked 77 extension identities to a campaign dubbed the 'Offside Wallet Theft Factory,' confirming 40 as malicious. These extensions impersonated popular wallets such as OKX, Rabby Wallet, and TronLink, often using similar names to deceive users.
Some of these malicious add-ons initially functioned as legitimate sports score applications, publishing live football and basketball scores. Over time, their code was quietly updated to include wallet-stealing malware, leveraging their existing install base and positive review history. The campaign, identified by shared code, infrastructure, and publishing patterns, was active from March 9 to August 3, with several extensions remaining live even after being reported.
Socket's research detailed various methods used by the malware, including fake wallet interfaces that captured typed recovery phrases or private keys, and modified versions of real wallet code that exfiltrated stored account data. Other extensions focused on collecting saved credentials and clipboard contents. The firm advised users who may have entered sensitive information into these extensions to treat their wallets as permanently compromised and transfer funds to a new, secure wallet.
