Malicious Firefox Add-ons Target Crypto Wallets in 'Offside Wallet Theft Factory' Campaign
Researchers at Socket have discovered that 40 malicious Firefox add-ons were used to target crypto wallets, with 9 of them originally distributing sports-score tools. The campaign, dubbed the 'Offside Wallet Theft Factory,' operated from March to August and affected at least 77 identities.
The 40 malicious add-ons used distinct attack paths, including remote-controlled phishing loaders, credential theft, and wallet-draining techniques. Seven were found to be remote-controlled phishing loaders, while 15 captured recovery phrases or private keys. Thirteen modified clones of Rabby wallet software sent serialized keyrings away before local encryption.
According to Mozilla, users who entered their secrets or used an affected build that transmitted its keyring should move remaining assets to a fresh crypto wallet created from a new recovery phrase. The company uses automated risk indicators and human review to identify malicious wallet add-ons and advises users to install only extensions linked from the wallet provider's official site.
Socket documented theft capability and exfiltration infrastructure but did not identify confirmed victims, attributable transactions, or a campaign loss total. The report noted that several campaign add-ons were still live when it was reported to Mozilla, with one being removed before publication.