A recent investigation has uncovered a group of 40 harmful Mozilla Firefox extensions that mimic Web3 services such as OKX and TronLink to pilfer cryptocurrency wallet details. The operation, identified as the Offside Wallet Theft Factory, has reportedly been in motion since March 2026, according to insights from the Socket Threat Research team.
Malicious Extensions and Their Operations
The fraudulent extensions are part of a larger network of 77 add-ons sharing common source codes and infrastructure. Of these, 40 have been explicitly marked as malicious, while the remaining 37 partake in a coordinated operation disguising as sports-related utilities. Although the latter group does not directly steal credentials, their deceptive nature and shared development history suggest malicious intent.
These extensions employ various tactics to siphon off sensitive wallet information. Some use threat actor-managed Supabase projects to dynamically serve phishing pages or decoy content. Others extract recovery phrases and private keys through Cloudflare Workers. Additionally, some versions of Rabby Wallet have been modified to exfiltrate serialized keyrings before they undergo local encryption.
Deceptive Practices and Distribution
The method of theft involves either creating a mock wallet webpage or embedding the malicious functionality directly within the extension. Initially, these extensions appeared on the official Firefox marketplace under the guise of sports score or utility shells. Over time, they pivoted to malware activities while retaining the same Firefox ID.
The sports score operation extensions display misleading functions related to popular sports like football and basketball, and use a hard-coded credential for the legitimate API-Sports service. Despite their legitimate appearances, they covertly market functions unrelated to sports, such as password generation and VPN access.
Implications and Ongoing Risks
Among the confirmed malicious extensions, some include Safe-Themes, Rabbit For Desktop, and several others masquerading under different names. These extensions pose a significant risk as a single installation can compromise valuable wallet credentials.
Security expert Kirill Boychenko notes that the low cost of publishing these disposable extensions explains the persistence of threat actors within the Firefox Add-ons ecosystem. By rotating names, cloning code, and distributing malicious functionalities across various platforms, these actors maintain a scalable and cost-effective operation despite the ephemeral nature of individual extensions.
In conclusion, the discovery of these malicious Firefox extensions underscores the importance of vigilance in the digital landscape. Users are advised to regularly update their security measures and stay informed about emerging threats to safeguard their cryptocurrency assets.
