August 25, 14:10

Firefox campaign links 77 fake extensions to crypto-stealing malware

Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware

Decrypt

Socket linked 77 counterfeit Firefox extension identities through shared code, infrastructure and publishing patterns. Socket confirmed 40 of the extensions as malicious. Mozilla signing records place the campaign from March 9 to August 3. Several extensions were still live when Socket reported them. The extensions impersonated OKX, Rabby Wallet, TronLink and other Web3 products. Some used characters that closely resembled the legitimate product names. Roughly half presented a wallet interface and asked users to import an existing wallet. Those extensions collected recovery phrases or private keys entered by users. Thirteen modified Rabby builds operated normally but sent stored account data to an outside server when it was saved. Five extensions collected saved credentials and clipboard contents. Thirty-seven other identities appeared to be password generators, dark mode toggles, VPNs, currency converters and note-taking tools. Those identities actually ran live sports-score applications. The applications shared one hardcoded credential for a legitimate sports data provider. Nine confirmed malicious extensions initially published football, basketball, NBA or American football score applications under the same Firefox IDs. Later updates replaced the score applications with wallet-stealing code. The updates retained the install base and review history built by the original applications. Socket named the campaign the Offside Wallet Theft Factory. Socket has not established that one operator controlled every extension. One counterfeit OKX wallet requested only storage and tabs permissions. The extension loaded a remote page and waited for users to enter a recovery phrase. Socket said permission reviews alone may not identify extensions with this behavior. Socket advised anyone who entered a recovery phrase or private key into one of the extensions to treat it as permanently compromised. Socket said users should move funds to a new wallet because uninstalling an extension does not revoke a phrase already sent elsewhere. The article also described browser extensions as a recurring route to crypto theft. It cited a Chrome extension that siphoned fees from Solana traders for months before detection. It also cited stealers hidden in pirated software, a fake Mac clipboard application and PC games distributed through Steam.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.