Security researchers identified 77 linked Firefox extensions, including 40 malicious add-ons designed to steal cryptocurrency recovery phrases and browser credentials.
Socket security researcher Kirill Boychenko said his team identified 77 linked Firefox extension identities, 40 confirmed to steal cryptocurrency wallet recovery phrases and other credentials, in a campaign active since at least March 2026, according to a Socket report published this month.
The campaign, dubbed the “Offside Wallet Theft Factory,” highlights the security risks associated with browser extensions that appear legitimate when downloaded from official marketplaces. Researchers said some of the extensions initially presented themselves as harmless utilities before being repurposed or used to deliver cryptocurrency-stealing infrastructure.
The findings are particularly significant for crypto users because a stolen recovery phrase can provide attackers with direct access to a wallet’s assets, making the consequences potentially immediate and irreversible.
Malicious Firefox extensions disguised as legitimate tools
Socket researchers said they identified 77 Firefox extension identities connected through several technical and behavioral indicators, including code reuse, cloned extensions, deceptive marketplace descriptions, author-selected add-on ID patterns, domain-like suffixes, cryptocurrency-wallet impersonation and version histories showing that some extensions had been repurposed.
The 0KX WEB3 listing inviting Firefox users to download a malicious extension
Of the 77 extensions, 40 were confirmed to be malicious, while another 37 were deceptive sports-score extensions that researchers said formed part of the broader campaign.
The sports-related extensions were designed around seemingly legitimate functions such as displaying football, basketball, NBA and hockey scores. Researchers said these extensions initially appeared harmless and used legitimate API-Sports credentials.
However, the extensions advertised unrelated features, including password generation, dark mode, VPN access, currency conversion, screenshots and note-taking.
According to Socket, this approach could help fraudulent add-ons appear more credible to users and marketplace operators before being transformed into cryptocurrency-stealing malware.
The researchers described the campaign as an example of how Malicious Firefox extensions can exploit users’ trust in ordinary browser utilities.
Socket’s Threat Research team said it was “tracking 77 Firefox extension identities linked through code reuse, cloned extensions, deceptive marketplace descriptions, author-selected add-on ID patterns and domain-like suffixes, cryptocurrency-wallet impersonation, and version histories showing extension repurposing.”
A fake OKX wallet leads users to a phishing page
One of the clearest examples uncovered by researchers was an extension called “0KX WEB3,” which imitates the branding of cryptocurrency exchange OKX by replacing the letter “O” with the number zero.
The extension was presented as a crypto wallet, but researchers found that it did not actually contain wallet functionality.
Instead, Malicious Firefox extensions such as this one can operate as delivery mechanisms for phishing pages. The 0KX WEB3 extension contained a local notepad that served as a cover, along with a hardcoded Supabase project URL and anonymous API key.
It also included a remotely configurable URL loader capable of displaying a supplied webpage inside the extension’s popup and opening it separately after installation or an update.
That infrastructure led Socket researchers to classify the extension as something different from a conventional information-stealing program.
The researchers said it “is therefore better classified as a remote-controlled phishing delivery extension than a conventional infostealer.”
The extension uses Supabase, a legitimate cloud platform, as part of its remote-control infrastructure. When a victim opens the add-on, the extension queries a table within the embedded Supabase project and retrieves the latest content.
Eventually, victims can be presented with a convincing wallet-import page.
If a user enters a wallet recovery phrase into that page, the information is transmitted to the attackers. For cryptocurrency users, that can expose the credentials needed to access funds stored in the associated wallet.
The incident demonstrates why Malicious Firefox extensions can be particularly dangerous when they imitate trusted financial services. A user may believe they are installing a wallet while actually installing a mechanism designed to direct them toward a phishing site.
Mozilla removes the fraudulent extensions
Socket reported its findings to Mozilla, which operates the Firefox Add-ons ecosystem.
Mozilla’s Add-ons Operations team responded by removing and blocklisting the fraudulent extensions from the official Firefox Add-ons Store. The company had also introduced a security mechanism for its Add-on Portal the previous year aimed at preventing waves of fraudulent cryptocurrency-wallet extensions.
The researchers welcomed the response, while stressing that removing individual extensions does not eliminate the broader threat.
“Even short-lived cryptocurrency wallet extensions can cause immediate and irreversible financial harm once victims expose recovery phrases or private keys,” — Socket researchers.
The researchers added that their work could help complement Mozilla’s own protections by identifying relationships between extensions and the infrastructure behind them.
“Our Firefox ecosystem coverage complements Mozilla’s protections by identifying related extensions, infrastructure, code reuse, version repurposing, and publishing patterns across the broader campaign,” — Socket researchers.
The speed of Mozilla’s response is significant because the campaign demonstrates how quickly browser add-ons can shift from apparently benign tools to mechanisms for credential theft.
Why Malicious Firefox extensions remain a broader threat
The campaign is not an isolated example of browser extensions being used to distribute malicious software.
Researchers have repeatedly identified malware in browser marketplaces, including Chrome’s Web Store. In April, dozens of extensions were reportedly linked to malware controlled by a single operator.
The underlying security problem extends beyond cryptocurrency.
A browser extension may provide useful services such as price tracking, ad blocking or AI-powered tools when initially installed, but researchers warn that an extension’s behavior can change after an update or through remotely controlled infrastructure.
That makes Malicious Firefox extensions a continuing concern even for users who avoid obviously suspicious software.
For cryptocurrency holders, the stakes can be particularly high. Unlike a compromised password that can potentially be reset, a wallet recovery phrase or private key can provide access to digital assets that may be difficult or impossible to recover once stolen.
The latest campaign therefore underscores a basic security principle: users should treat browser extensions that request wallet recovery phrases or private keys with extreme caution.
The discovery of Malicious Firefox extensions also shows why users should verify wallet software through official channels and carefully inspect extension names, publishers and requested permissions before installation.
The “Offside Wallet Theft Factory” campaign may have been disrupted after Mozilla removed the identified add-ons, but the techniques behind it remain relevant. As browser extensions become increasingly capable and remotely configurable, attackers have more opportunities to turn trusted software ecosystems into delivery channels for phishing and credential theft.
The campaign ultimately reinforces the need for continued monitoring by browser vendors, security researchers and cryptocurrency users alike.
Malicious Firefox extensions may disappear from an official store, but the infrastructure, code and social-engineering techniques behind them can be reused in new campaigns.
Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.