AIO APEX

40 malicious Firefox extensions impersonate OKX, Rabby, and TronLink to steal crypto wallet secrets

The Hacker News
Share:
40 malicious Firefox extensions impersonate OKX, Rabby, and TronLink to steal crypto wallet secrets

Security researchers at Socket have identified 40 malicious Firefox extensions actively stealing cryptocurrency wallet secrets by impersonating popular Web3 tools including OKX, Rabby Wallet, and TronLink. The extensions are part of a larger network of 77 linked identities that share source code, publishing infrastructure, and version histories, according to a report published by Socket's Threat Research team and first covered by The Hacker News.

The campaign, which Socket has dubbed the Offside Wallet Theft Factory, is believed to have been active since March 2026 and has not been attributed to any known threat actor or group.

How the Extensions Steal Wallet Data

Researcher Kirill Boychenko detailed several distinct theft mechanisms across the 40 confirmed-malicious extensions. Fifteen capture recovery phrases, private keys, and other wallet secrets and exfiltrate them through Cloudflare Workers. Thirteen modified builds of the legitimate Rabby Wallet extension exfiltrate serialized keyrings before local encryption can protect them. Five more capture credentials and clipboard data through hard-coded command-and-control infrastructure, and seven use threat-actor-controlled Supabase projects as remote switches to serve phishing pages or decoy content dynamically, making the malicious behavior harder to detect during automated review.

The wallet-stealing extensions used two primary techniques: loading a fake wallet interface remotely, or building the theft functionality directly into the extension itself.

The Sports-Score Disguise

A notable feature of the campaign is its use of disguise-and-pivot tactics. Thirty-seven of the 77 linked extensions present as sports-score or utility tools — covering football, basketball, the NBA, and hockey — while marketing unrelated features like password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking. These extensions share a hard-coded credential for API-Sports, a legitimate real-time sports data service, lending them functional cover.

Socket found that at least nine of the confirmed-malicious wallet-stealing identities followed this exact pattern: an extension first published as an innocuous sports-score shell under a given Firefox ID, later updated under that same ID to include wallet- or credential-stealing code. Because Firefox add-on reviews primarily assess the initially submitted version, this update-after-approval pattern let the malicious versions bypass the marketplace's original vetting.

Why This Matters Beyond Crypto Users

The campaign illustrates a broader weakness in browser extension marketplaces: legitimate-looking utility extensions can be repurposed into credential-stealing malware long after initial approval, without triggering a new full review in every case. For users who don't actively audit which browser extensions they've installed and what those extensions were updated to do, the sports-score-to-wallet-drainer pivot is effectively invisible until funds are already gone.

Socket's research also found the remaining 31 confirmed-malicious identities lack the sports API integration but contain their own confirmed wallet- or credential-stealing functionality, suggesting the operators are running multiple parallel disguise strategies rather than relying on a single template.

Users who have Firefox extensions related to cryptocurrency wallets, sports scores, VPN access, or password generation installed should review their extension list immediately, cross-reference installed extension IDs against Socket's published indicators of compromise, and remove anything unrecognized or unused. Anyone who suspects an affected extension may have accessed a wallet should move funds to a new wallet with a freshly generated seed phrase rather than reusing existing keys.

Originally reported by The Hacker News. Read the original article for additional details.

View original source
Share: