16 Malicious Firefox Extensions Disguised as Crypto Wallets Steal Recovery Phrases
Researchers identify cluster of deceptive add-ons targeting cryptocurrency users on Mozilla Firefox

Key Takeaways
- 16 malicious Firefox extensions discovered masquerading as crypto wallet tools
- Extensions intercept recovery phrases and private keys during import flows
- Data exfiltrated to remote servers controlled by threat actors
- Distribution via addons.mozilla.org and similar channels
Related Security News

Low-cost Android phones ship with residential proxy malware
Security researchers have identified a malware campaign, tracked as 'Midnight Mimosa', where malicious software is embedded in the firmware of low-cost Android smartphones. The compromise enables silent app installation, ad fraud, and the conscription of devices into residential proxy networks without user consent.




