Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 6 sources · 11 days · First seen · Last updated
Browser extension cryptocurrency theft campaigns
Overview
Security researchers have identified large-scale malware campaigns utilizing malicious browser extensions to facilitate cryptocurrency theft.
Initial reports identified the ‘Offside Wallet Theft Factory’ campaign, which involved approximately 40 malicious Firefox extensions. These extensions masqueraded as legitimate Web3 products, such as OKX and TronLink, to exfiltrate recovery phrases and private keys. The campaign, active since March 2026, utilized Cloudflare Workers and Supabase projects to manage data exfiltration and phishing pages.
Subsequent findings expanded the scope to include a supply chain campaign targeting Google Chrome and Microsoft Edge users. This operation involved both newly created extensions and those acquired from legitimate publishers. In one instance, a hijacked extension reached approximately 70,000 Chrome users and 10,000 Edge users.
The malware in these campaigns is designed to hijack ‘Connect Wallet’ and ‘Swap’ buttons to drain assets across networks including EVM, Solana, and Tron. It also possesses the capability to replace hardware wallet websites with phishing pages, steal session tokens from major exchanges like Coinbase and Binance, and bypass security measures by removing Content Security Policy (CSP) headers.
Entities
Socket Threat Research · OKX · Socket · Google Chrome · Mozilla Firefox
Timeline
-
12 days ago
[TECHNOLOGY] 6 sourcesBrowser extensions weaponized in cryptocurrency theft campaignA supply chain attack involving 19 Chrome and Edge extensions has been uncovered, targeting cryptocurrency users to steal funds, credentials, and session tokens via malicious updates.
-
23 days ago
[TECHNOLOGY] 2 sourcesFirefox extensions identified in cryptocurrency wallet theft campaignA campaign called ‘Offside Wallet Theft Factory’ uses 40 malicious Firefox extensions to steal cryptocurrency recovery phrases and private keys by posing as legitimate Web3 products.
Sources
csoonline.com.au · cybernoz.com · generation-nt.com · iltalehti.fi · news.yam.md · safenews.md