A network of fake Firefox extensions has been used to target cryptocurrency users by posing as well-known wallet brands and other browser tools, according to security firm Socket. The company said it linked 77 extension identities to a campaign it calls the Offside Wallet Theft Factory, and confirmed 40 of them as malicious.

The add-ons allegedly imitated products including OKX, Rabby Wallet and TronLink, using names and interfaces designed to appear legitimate. Socket said the goal was to trick users into handing over recovery phrases or private keys, while some variants also exfiltrated data already stored in the browser.

Wallet brands imitated inside Firefox

Socket said the campaign operated like a production line of counterfeit wallet extensions for Firefox. The reported extensions copied trusted Web3 tools closely enough to make the prompts and screens look convincing, increasing the chance that a user would treat them as genuine software.

According to the report, several of the add-ons asked users to enter a recovery phrase or private key directly into the extension. If that information was submitted, it could then be sent to attackers, giving them access to the victim’s wallet.

The firm said some samples were modified builds of Rabby Wallet. Those versions allegedly sent stored data to outside servers without the user’s knowledge. Other extensions were also described as collecting saved credentials and clipboard contents.

Benign-looking tools used as cover

Socket said not every extension identity in the cluster presented itself as a wallet. It found 37 identities that appeared to be unrelated utilities, such as password generators, dark mode toggles, VPNs, currency converters and note-taking apps.

Behind those labels, the extensions reportedly ran live sports-score applications and shared a single credential for a legitimate sports data provider. Socket said this common infrastructure helped connect the separate listings to the same broader operation.

Installed apps later switched into stealers

One of the more notable tactics described in the report involved extensions that changed behavior after installation. Socket said nine Firefox add-ons first operated as sports-score apps and were later updated into wallet-stealing extensions.

That approach would allow the operators to build an install base and a usage history before turning the software into malware. In practice, users who had installed what seemed to be a harmless score app could later receive an update that presented wallet-related prompts or theft functions.

How one fake OKX extension worked

Socket highlighted a counterfeit OKX wallet as an example of the campaign’s design. The extension reportedly requested only storage and tabs permissions, a limited set that could make it seem less suspicious to users reviewing the install prompt.

The add-on then loaded a remote page and waited for the target to type in a recovery phrase. Socket noted that removing the extension afterward would not undo the theft: once a phrase has been transmitted elsewhere, uninstalling the add-on does not revoke or secure that seed phrase.

What is confirmed so far

Based on the information published by Socket, the confirmed findings are the 77 extension identities tied to the campaign, the 40 that the firm classified as malicious, and the use of wallet impersonation and non-wallet utility listings as part of the same operation.

The immediate implication is limited but important: users who entered a recovery phrase or private key into one of the cited extensions cannot rely on uninstalling the add-on as a fix. The next confirmed step from the report is Socket’s identification of the extension cluster and the specific tactics it says were used to lure victims and capture sensitive wallet data.

Source: decrypt.co