Malicious Firefox Add-Ons Target Crypto Wallets in Massive Phishing Campaign
A recent report by Socket, a software supply-chain security firm, revealed that 40 malicious Firefox add-ons targeted cryptocurrency wallets. The campaign, dubbed the 'Offside Wallet Theft Factory,' operated from at least March to August and affected 77 identities. Of these, 40 had confirmed malicious behavior, including phishing, credential theft, and wallet-draining techniques.
The nine affected add-on IDs had previously distributed sports-score tools under the same names, raising suspicions about their legitimacy. Mozilla's signing records showed that the original versions of these add-ons were submitted for review as early as March 9. However, it was not until August that the malicious behavior was confirmed.
Socket's analysis revealed that uninstalling the malicious add-ons would not be enough to revoke exposed secrets, such as recovery phrases or private keys. As a result, anyone whose wallet was compromised by one of these add-ons should treat their wallet as compromised and take necessary precautions.