Quick Takeaways
- Malicious Firefox extensions, masquerading as Web3 wallets and popular apps, exfiltrate private keys, recovery phrases, and credentials, posing a significant threat to cryptocurrency security.
- Attackers leverage shared code, infrastructure, and dynamic remote loading via Supabase and Cloudflare to distribute and update wallet-stealing malware covertly.
- The ecosystem’s persistence is driven by economic incentives, as a single successful installation can result in thefts worth far more than the cost of these ephemeral malicious extensions.
Threat Overview, Attack Techniques, and Targets
A group of 40 malicious Firefox extensions have been identified. These extensions pretend to be popular Web3 products like OKX, Rabby Wallet, and TronLink. Their goal is to steal cryptocurrency wallet secrets. This set of add-ons is part of a larger group of 77 extensions sharing similar code and infrastructure. The activity has been ongoing since March 2026, but no specific attacker group has been linked to these attacks.
The attackers use different methods to trick users. Some extensions load fake wallet pages remotely, while others include malicious code directly. Seven extensions use server-controlled projects to show fake content or phishing pages, while 15 extensions capture wallet secrets like recovery phrases and private keys. These secrets are then sent back to attackers through cloud services like Cloudflare Workers. Thirteen modified extensions exfiltrate wallet key data before encrypting it locally. The remaining five extensions gather credentials and clipboard data through command-and-control infrastructure.
Many of these extensions first appeared on the official Firefox marketplace as sports or utility tools. Later, they were secretly changed into wallet-stealing malware under the same extension ID. The deception includes sports score features that share API keys but secretly include malware capabilities. Some extensions hide malicious functions in ordinary-looking add-ons, making them easier to distribute and harder to detect.
Impact, Security Implications, and Remediation Guidance
These malicious extensions pose serious risks. They can steal sensitive wallet information like recovery phrases, private keys, and credentials. If this data is stolen, attackers can take control of users’ cryptocurrency assets. The deception also increases the likelihood of users unknowingly exposing their wallet secrets.
The activities can compromise user security and lead to financial losses. Because the attackers use sophisticated methods such as remote content loading, shared infrastructure, and code reuse, defense can be difficult. Users should avoid installing extensions from untrusted sources or ones that seem suspicious.
Since no specific remediation guidance is provided here, affected users should contact the vendors of their Web3 wallets or review official security alerts. It is recommended for users to remove any suspicious extensions and monitor their wallets for unusual activity. For cybersecurity teams, it is important to stay updated on threat actor tactics and consider blocking or auditing extensions that could be malicious.
Expand Your Tech Knowledge
Learn how the Internet of Things (IoT) is transforming everyday life.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
