mimile
Back to feed

Socket identifies 40 malicious Firefox add-ons targeting crypto wallets

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Socket identifies 40 malicious Firefox add-ons targeting crypto wallets

Software supply-chain security firm Socket identified 40 Firefox add-on identities with confirmed malicious behavior, including crypto wallet draining. Nine of these identities previously distributed sports-score tools under the same IDs. Mozilla removed one live phishing add-on, but confirmed victims and total losses remain unidentified.

Key Facts

  • Socket identified 40 Firefox add-on identities with confirmed malicious behavior, including crypto wallet draining.
  • Nine of the 40 malicious identities previously distributed sports-score tools under the same IDs.
  • The campaign operated from at least March into August, with Mozilla signing records for the original 59 analyzed versions running from March 9 through Aug. 3.
  • Mozilla removed one live phishing add-on, 0KX WEB3, which had seven users during analysis.
  • Exposed recovery phrases, private keys, and serialized wallet keyrings remain compromised after uninstalling, requiring migration to fresh wallets.

Malicious Add-on Identities

Socket found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto. Nine of these identities had previously distributed sports-score tools under the same IDs. The Aug. 19 report linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 containing confirmed malicious behavior. The other 37 were deceptive or suspicious sports-score shells whose analyzed versions contained no confirmed theft payload. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July.

Attack Paths and Compromise

The 40 malicious identities used distinct attack paths: seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys, or other crypto wallet secrets, 13 modified clones of Rabby wallet software sent serialized keyrings away before local encryption, and five collected credentials and clipboard data. Anyone whose recovery phrase, private key, or wallet keyring reached one of the malicious versions must treat that wallet as compromised because uninstalling the add-on cannot revoke an exposed secret. Socket said several campaign add-ons were still live when it reported them to Mozilla. Its report noted that the remote-controlled phishing add-on 0KX WEB3 was live with seven users during analysis, and Mozilla removed it before publication.

1 source

Socket identifies 40 malicious Firefox add-ons targeting crypto wallets