Interestana
Home/News/40 Malicious Firefox Extensions Steal Crypto Wallet Secrets
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

40 Malicious Firefox Extensions Steal Crypto Wallet Secrets

40 Malicious Firefox Extensions Steal Crypto Wallet Secrets

A total of 40 malicious extensions have been identified within the Mozilla Firefox browser, designed to impersonate legitimate Web3 products and steal cryptocurrency wallet secrets. These extensions, discovered by the Socket Threat Research team, are part of a larger campaign involving 77 browser add-ons that exhibit shared source code and overlapping infrastructure. The operation has been named the "Offside Wallet Theft Factory." The identified extensions specifically targeted users of popular Web3 wallets and services, including OKX, Rabby Wallet, and TronLink, by presenting themselves as official applications or tools related to these platforms. By tricking users into installing these fraudulent extensions, the attackers aimed to gain unauthorized access to sensitive information stored within cryptocurrency wallets. This includes private keys, seed phrases, and other credentials necessary for managing digital assets. The Socket Threat Research team's analysis revealed significant code reuse and shared infrastructure across these 77 add-ons, indicating a coordinated and sophisticated operation. The campaign's primary objective was to compromise the security of cryptocurrency holdings by exploiting user trust in familiar Web3 brands. The discovery highlights a persistent threat vector within the browser extension ecosystem, where malicious actors leverage the perceived convenience and functionality of add-ons to conduct phishing and theft operations. The researchers have not yet disclosed the exact methods used by the extensions to exfiltrate wallet data, but such attacks typically involve intercepting user inputs, manipulating transaction details, or directly accessing stored wallet information. The broad scope of the campaign, encompassing 77 add-ons, suggests a significant effort to maximize the potential victim pool. The specific targeting of Web3 products indicates a growing trend of cybercriminals focusing on the cryptocurrency space due to the high value of digital assets. The Socket Threat Research team's findings underscore the importance of user vigilance when installing browser extensions, particularly those that interact with financial applications or sensitive personal data. Users are advised to download extensions only from official sources, scrutinize developer information, read reviews carefully, and be wary of extensions requesting excessive permissions. The ongoing threat posed by such malicious extensions necessitates continuous monitoring and rapid response from browser vendors and security researchers to protect users from financial loss and data compromise.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next