Malicious Firefox Add-ons Exposed Crypto Wallet Secrets
Firefox add-on identities with confirmed malicious behavior have been identified by Socket, a software supply-chain security firm. The investigation found 40 malicious Firefox add-ons that targeted crypto wallets, including nine that started as sports-score tools.
The affected add-ons were able to drain cryptocurrency and expose recovery phrases, private keys, and serialized wallet keyrings. Even after uninstalling the malicious add-ons, the compromised secrets remain exposed, requiring migration to fresh wallets.
According to Socket's report, the campaign operated from at least March into August, with Mozilla signing records for the original versions analyzed by Socket running from March 9 through Aug. 3.
The affected IDs were identified as Firefox IDEarlier sports versionLater malicious versionbright-save-feed@tabtools.orgQuick Quick 7.4.0Rabbit For Desktop 8.20.10swift-clip-link@fasttools.coDial Open Pro 7.23.25Web3 & EVM 9.50.10deep-tip-sharp@browsify.coQuick Shield 5.7.1Rby-WALLEТ 6.7.10bolt-save-vault@devplugs.coLite Swatch 6.5.21
Users exposed to the compromised add-ons should take precautions, including migrating their assets to fresh wallets created from new recovery phrases.