Ravie LakshmananAug 20, 2026Browser Security / Cryptocurrency
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.
According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to have been active since March 2026. The activity has not been attributed to any known threat actor or group.
“Extension-level analysis confirms 40 as malicious,” security researcher Kirill Boychenko said. “Another 37 form a coordinated multi-sport score-shell operation. Their analyzed builds contain no confirmed credential- or wallet-stealing payloads, but their deceptive functionality, shared publishing artifacts, and version histories indicate malicious intent.”
Among those 40 extensions, seven use threat actor-controlled Supabase projects as remote switches to server phishing or decoy content dynamically; 15 capture recovery phrases, private keys, and other wallet secrets, and exfiltrate them through Cloudflare Workers; 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption; and the remaining five capture credentials and clipboard data through hard-coded command and control (C2) infrastructure.
The wallet secrets are stolen using two methods: either remotely loading a fake wallet page or baking the functionality into the extension itself. In some cases, the add-ons first appeared on the official Firefox extensions marketplace as sports score or utility shells, before they were turned into wallet-stealing malware under the same Firefox ID.
The 37 extensions related to the sports score operation contain deceptive implementations spanning football, basketball, NBA, and hockey, and share a hard-coded credential for legitimate API-Sports, a legitimate service that delivers real-time sports data, while marketing unrelated functions such as password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking.
“Historical versions of nine confirmed malicious identities also used sports-score shells spanning football, basketball, NBA, and American football before later versions under the same Firefox IDs were repurposed into wallet-stealing extensions,” Socket said.
“The other 31 confirmed malicious identities lack the sports API integration but contain confirmed malicious wallet- or credential-stealing functionality.”
The names of some of the malicious extensions are below –
- Safe-Themes – Browser Extension (bliss-heaven@webbrol.com)
- Rabbit For Desktop (bright-save-feed@tabtools.org)
- ℞ab␢y Wa❘Iet (flex-clock-dash@extrakits.com)
- Rabb-Walӏet CryptoPortfolio (free-note-bolt@webtools.co)
- RABB-Walӏet Web3 & EVM (safe-stat-pure@proaddons.net)
- Rabbit/WALLET – EVM (sharp-stat-gear@netplugs.net)
“A single successful installation can expose a recovery phrase, private key, or wallet state worth far more than the cost of repeatedly publishing disposable extensions,” Boychenko said.
“That economics helps explain the threat actors’ persistence in targeting the Firefox Add-ons ecosystem even when individual extensions are short-lived and ultimately removed. Rotating names and IDs, repurposing existing extension identities, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure make repeated publication cheap and scalable.”
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

