< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Firefox extensions identified in cryptocurrency wallet theft campaign

Security researchers have identified a campaign known as ‘Offside Wallet Theft Factory’ involving 40 malicious Firefox extensions designed to steal cryptocurrency wallet secrets. The extensions masquerade as legitimate Web3 products, including OKX, Rabby Wallet, and TronLink.

According to analysis by the Socket Threat Research team, these 40 extensions are part of a larger group of 77 add-ons that share code and infrastructure. The campaign has reportedly been active since March 2026. The malware employs various technical methods to exfiltrate sensitive data such as recovery phrases, private keys, and serialized keyrings.

Specific tactics include using Cloudflare Workers for data exfiltration and leveraging threat-actor-controlled Supabase projects to dynamically serve phishing pages or decoy content. In some instances, extensions initially appeared on the official Firefox marketplace as benign utility or sports score tools before being repurposed as malware under the same Firefox ID.

Entities

Cloudflare · Mozilla Firefox · OKX · Socket Threat Research · Supabase