Software supply-chain security firm Socket identified 40 malicious Firefox add-on identities built to target cryptocurrency wallets, with nine of them beginning as benign sports-score tools before being repurposed. The report, published on Aug. 19, linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 showing confirmed malicious behavior and 37 remaining deceptive or suspicious sports-score shells without confirmed theft payloads.
The campaign operated from at least March into August. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July. Among the nine identities that shifted from sports utilities to malicious versions, examples included bright-save-feed@tabtools.org moving from Quick 7.4.0 to Rabbit For Desktop 8.20.10, and swift-clip-link@fasttools.co moving from Dial Open Pro 7.23.25 to Web3 & EVM 9.50.10. Other IDs followed similar patterns, repackaging names such as Quick Shield, Lite Swatch, Key Pulse, Timer Pulse and Pomodoro Plus into Rabbit or WALLET variants.
Socket classified the 40 malicious identities into distinct attack paths. Seven were remote-controlled phishing loaders, 15 captured recovery phrases, private keys or other crypto wallet secrets, 13 modified clones of Rabby wallet software sent serialized keyrings away before local encryption, and five collected credentials and clipboard data. The report warned that a recovery phrase or private key can restore a wallet elsewhere, while a serialized keyring exposes the wallet’s account state before encryption can protect it. Anyone who entered secrets or used an affected build that transmitted its keyring should move remaining assets to a fresh wallet created from a new recovery phrase. Users exposed only to credential and clipboard collection should change affected passwords, terminate active sessions where possible, and verify copied destination addresses.
Socket noted that several campaign add-ons were still live when reported to Mozilla. The remote-controlled phishing add-on 0KX WEB3 was live with seven users during analysis, and Mozilla removed it before publication. Mozilla said it uses automated risk indicators and human review to identify malicious wallet add-ons and advises users to install only extensions linked from a wallet provider’s official site. The research documented theft capability and exfiltration infrastructure, but did not identify confirmed victims, attributable transactions, or a total campaign loss. The disclosure is being treated as a security event rather than a market or valuation signal.