
40 Malicious Firefox Extensions Disguised as Web3 Products Identified in 'Offside Wallet Theft Factory' Campaign
Researchers from Socket Threat Research have identified 40 malicious Mozilla Firefox extensions that pose as legitimate Web3 products, including OKX Wallet, Rabby Wallet, and TronLink, to facilitate cryptocurrency wallet theft. These extensions are part of a larger campaign dubbed "Offside Wallet Theft Factory," which encompasses 77 browser add-ons sharing source code and infrastructure overlaps. The malicious extensions were designed to mimic the appearance and functionality of trusted wallet interfaces, tricking users into revealing private keys or seed phrases, which were then exfiltrated to attacker-controlled servers. The findings highlight a significant threat to the Firefox add-on ecosystem and users interacting with decentralized finance (DeFi) platforms.