Overview
Security researchers at Socket Threat Research have uncovered a campaign dubbed Offside Wallet Theft Factory, involving 40 malicious Mozilla Firefox extensions masquerading as legitimate Web3 products like OKX, Rabby Wallet, and TronLink. These extensions were designed to steal cryptocurrency wallet secrets, with activity traced back to March 2026.
Malicious Extension Tactics
- Supabase remote switches: 7 extensions dynamically served phishing or decoy content.
- Cloudflare Workers exfiltration: 15 extensions captured recovery phrases, private keys, and wallet secrets.
- Modified Rabby Wallet builds: 13 extensions exfiltrated serialized keyrings before encryption.
- Hard‑coded C2 infrastructure: 5 extensions stole credentials and clipboard data.
The theft occurred either by loading fake wallet pages remotely or embedding malicious functionality directly into the extension.
Sports Score Shells
Interestingly, 37 related extensions posed as sports score utilities (football, basketball, NBA, hockey) but shared deceptive publishing artifacts.
- API‑Sports credential abuse: Hard‑coded credentials linked to legitimate sports data services.
- Repurposed identities: Historical versions of nine malicious extensions began as sports shells before being converted into wallet‑stealing malware.
Examples of Malicious Extensions
- Safe‑Themes – Browser Extension (bliss-heaven@webbrol.com)
- Rabbit For Desktop (bright-save-feed@tabtools.org)
- ℞ab␢y Wa❘Iet (flex-clock-dash@extrakits.com)
- Rabb‑Walӏet CryptoPortfolio (free-note-bolt@webtools.co)
- RABB‑Walӏet Web3 & EVM (safe-stat-pure@proaddons.net)
- Rabbit/WALLET – EVM (sharp-stat-gear@netplugs.net)
Each installation risked exposing recovery phrases, private keys, or wallet states—assets worth far more than the cost of publishing disposable extensions.
Defensive Guidance
Users and organizations should:
- Audit installed extensions: Remove suspicious or unfamiliar add‑ons.
- Verify wallet apps: Only download from official sources.
- Monitor clipboard activity: Watch for unauthorized access to sensitive data.
- Educate users: Highlight risks of fake Web3 products.
- Report malicious extensions: Help Mozilla track and remove fraudulent add‑ons.
Expert in the Cloud Insight
This campaign demonstrates the economic persistence of threat actors in targeting browser ecosystems. By rotating names, repurposing identities, and splitting functionality across multiple extensions, attackers make malicious publication cheap and scalable. For Web3 users, the lesson is clear: browser extensions are a high‑risk vector for wallet theft, and vigilance is essential.
Leave a Reply