Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Firefox Extensions Exploit Web3 Users to Steal Wallet Data

Firefox Extensions Exploit Web3 Users to Steal Wallet Data

Posted on August 21, 2026 By CWS

A recent investigation has uncovered a group of 40 harmful Mozilla Firefox extensions that mimic Web3 services such as OKX and TronLink to pilfer cryptocurrency wallet details. The operation, identified as the Offside Wallet Theft Factory, has reportedly been in motion since March 2026, according to insights from the Socket Threat Research team.

Malicious Extensions and Their Operations

The fraudulent extensions are part of a larger network of 77 add-ons sharing common source codes and infrastructure. Of these, 40 have been explicitly marked as malicious, while the remaining 37 partake in a coordinated operation disguising as sports-related utilities. Although the latter group does not directly steal credentials, their deceptive nature and shared development history suggest malicious intent.

These extensions employ various tactics to siphon off sensitive wallet information. Some use threat actor-managed Supabase projects to dynamically serve phishing pages or decoy content. Others extract recovery phrases and private keys through Cloudflare Workers. Additionally, some versions of Rabby Wallet have been modified to exfiltrate serialized keyrings before they undergo local encryption.

Deceptive Practices and Distribution

The method of theft involves either creating a mock wallet webpage or embedding the malicious functionality directly within the extension. Initially, these extensions appeared on the official Firefox marketplace under the guise of sports score or utility shells. Over time, they pivoted to malware activities while retaining the same Firefox ID.

The sports score operation extensions display misleading functions related to popular sports like football and basketball, and use a hard-coded credential for the legitimate API-Sports service. Despite their legitimate appearances, they covertly market functions unrelated to sports, such as password generation and VPN access.

Implications and Ongoing Risks

Among the confirmed malicious extensions, some include Safe-Themes, Rabbit For Desktop, and several others masquerading under different names. These extensions pose a significant risk as a single installation can compromise valuable wallet credentials.

Security expert Kirill Boychenko notes that the low cost of publishing these disposable extensions explains the persistence of threat actors within the Firefox Add-ons ecosystem. By rotating names, cloning code, and distributing malicious functionalities across various platforms, these actors maintain a scalable and cost-effective operation despite the ephemeral nature of individual extensions.

In conclusion, the discovery of these malicious Firefox extensions underscores the importance of vigilance in the digital landscape. Users are advised to regularly update their security measures and stay informed about emerging threats to safeguard their cryptocurrency assets.

The Hacker News Tags:browser security, Cryptocurrency, cyber threats, Cybersecurity, Extensions, Firefox, Malware, threat analysis, wallet theft, Web3

Post navigation

Previous Post: Zyxel Fixes Critical Command Injection in Access Points

Related Posts

GlassWorm Malware Disrupted in Major Supply Chain Attack GlassWorm Malware Disrupted in Major Supply Chain Attack The Hacker News
Cloud Tenants Could Threaten Power Grids Without Exploits Cloud Tenants Could Threaten Power Grids Without Exploits The Hacker News
New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login The Hacker News
Weekly Cybersecurity Recap: Major Threats and Developments Weekly Cybersecurity Recap: Major Threats and Developments The Hacker News
INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty The Hacker News
Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices Akira Ransomware Exploits SonicWall VPNs in Likely Zero-Day Attack on Fully-Patched Devices The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Firefox Extensions Exploit Web3 Users to Steal Wallet Data
  • Zyxel Fixes Critical Command Injection in Access Points
  • Manic Malware Targets Android Devices with Innovative Techniques
  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Firefox Extensions Exploit Web3 Users to Steal Wallet Data
  • Zyxel Fixes Critical Command Injection in Access Points
  • Manic Malware Targets Android Devices with Innovative Techniques
  • Hackers Exploit Microsoft 365 to Divert Payments
  • CDN Tsunami Threat: HTTP/3 Amplification in Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark