Firefox Extensions Impersonate Crypto Wallets to Steal Recovery Phrases
A group of malicious Firefox extensions has been linked to a campaign called the Offside Wallet Theft Factory, according to security firm Socket. The campaign, which ran from March 9 to August 3, created 77 extension identities, with 40 confirmed as malicious.
The extensions impersonated popular crypto wallet providers such as OKX, Rabby Wallet, and TronLink, often using characters that closely resembled the real names. Roughly half of the malicious extensions presented a convincing wallet interface and asked users to import an existing wallet, harvesting recovery phrases or private keys in the process.
Another 13 modified builds of Rabby behaved normally while sending the wallet's stored account data to an outside server as it was saved. Five collected saved credentials and clipboard contents instead.
Socket also discovered that nine extensions started as sports-score apps, publishing live scores before being converted into wallet-stealing code in later updates. The security firm has not established a single operator behind every extension.
Users who entered recovery phrases or private keys into one of these extensions should treat their funds as 'permanently compromised' and move them to a new wallet, Socket advised, since uninstalling an extension does not revoke a phrase already sent elsewhere.