Malicious Firefox add-ons impersonate Web3 wallets to steal secrets

Socket Threat Research has identified 40 malicious Mozilla Firefox extensions that impersonate Web3 products, including OKX, Rabby Wallet and TronLink, to steal cryptocurrency wallet secrets. The activity, dubbed Offside Wallet Theft Factory, is believed to have been active since March 2026 and has not been attributed to a known threat actor or group.
The confirmed malicious extensions sit within a broader cluster of 77 Firefox add-ons that share source-code and infrastructure overlaps. Socket said 37 of those add-ons form a coordinated multi-sport score-shell operation. Their analysed builds did not contain confirmed wallet- or credential-stealing payloads, but their deceptive functions, publishing artefacts and version histories indicated malicious intent.
Two paths to wallet theft
The campaign used two principal approaches. Extensions either loaded a fake wallet page remotely or contained the theft functionality directly in the add-on. In both cases, the target was highly sensitive wallet material: recovery phrases, private keys and wallet state.
Seven of the 40 confirmed malicious extensions used threat actor-controlled Supabase projects as remote switches, dynamically directing users to phishing or decoy content. Fifteen captured recovery phrases, private keys and other secrets, then exfiltrated them through Cloudflare Workers. A further 13 were modified Rabby Wallet builds that exfiltrated serialized keyrings before local encryption. The remaining five captured credentials and clipboard data through hard-coded command-and-control infrastructure.
Sports shells masked changing intent
Some extensions first appeared in the official Firefox extensions marketplace as sports-score or utility shells before being converted into wallet-stealing malware under the same Firefox ID. The related score operation covered football, basketball, NBA and hockey, while sharing a hard-coded credential for API-Sports, a legitimate real-time sports-data service.
Those add-ons were marketed with unrelated functions, including password generation, dark mode, VPN access, currency conversion, screenshot capture and note-taking. Socket found that historical versions of nine confirmed malicious identities used sports-score shells, including football, basketball, NBA and American football, before later versions under the same IDs were repurposed for wallet theft.
The pattern adds to the browser-focused credential risks seen in browser-focused credential theft risks and shows why extension identity alone is not a durable trust signal when an existing listing can change its purpose over time. Rotating names and IDs, cloning code, and splitting functionality among extensions, remote pages and cloud services can make repeat publication cheap and scalable.
Business implication
Organizations using browser wallets or Web3 services should inventory installed extensions, remove those without a clear operational purpose, and scrutinise publisher identity and requested permissions before deployment. Security teams should also account for extension updates and changes of function, rather than treating marketplace approval or a familiar Firefox ID as a permanent assurance of safety.

