Socket Threat Research identified 40 malicious Firefox extensions stealing cryptocurrency wallet credentials by impersonating legitimate Web3 products like OKX, Rabby Wallet, and TronLink. The extensions form part of a larger operation dubbed the Offside Wallet Theft Factory, which comprises 77 browser add-ons sharing common source code and infrastructure.

The threat actors behind this campaign deployed extensions across Mozilla's official add-on store, exploiting user trust in Firefox's review process. Users installing what they believed were authentic wallet management tools instead granted attackers direct access to private keys, seed phrases, and transaction authorization capabilities. The fake extensions mimicked the user interface and branding of legitimate platforms, making detection difficult for non-technical users.

Socket researchers traced the malware cluster through infrastructure connections and code similarities across all 77 add-ons. The broader operation extends beyond the 40 Firefox-specific extensions, suggesting the attackers maintain parallel campaigns across multiple browsers and platforms. This modular approach allows rapid deployment of new variants when existing extensions face removal.

The stolen credentials enable attackers to drain cryptocurrency wallets entirely. Unlike traditional financial theft, blockchain transactions are irreversible. Victims lose funds permanently once attackers gain private key access. The campaign targets users actively engaged in Web3, typically holding material cryptocurrency holdings.

OKX, a major cryptocurrency exchange, and Rabby Wallet, a popular browser-based wallet combining multi-chain support with security features, represent high-value targets. TronLink, the wallet for the TRON blockchain network, rounds out the impersonation targets. Each platform serves millions of users, providing attackers with a large attack surface.

Mozilla has removed confirmed malicious extensions from the Firefox Add-ons store following Socket's disclosure. However, attackers likely uploaded variants during the research period, and some malicious extensions may remain undetected. Users who installed any suspicious wallet extensions should immediately transfer cryptocurrency to cold storage wallets controlled through hardware devices. Additionally, they should rotate all private keys and seed phrases associated with affected wallets.

The Offside Wallet Theft Factory demonstrates how browser extension marketplaces remain attractive targets despite security review processes. Attackers succeed by using legitimate-looking source code, proper permissions documentation, and slow-moving credential exfiltration that avoids automated detection. The operation shows technical sophistication: infrastructure coordination across dozens of variants, proper obfuscation, and staging infrastructure separate from active theft operations.

Organizations and cryptocurrency custodians should implement network controls blocking known malicious extension C2 infrastructure. Enterprise security teams should audit Firefox extension deployments, particularly in environments where employees manage cryptocurrency or access exchange accounts.

The campaign underscores the broader risk landscape for browser extensions. Extensions operate with elevated privileges inside the browser sandbox, accessing all visited websites and user interactions. Malicious extensions can intercept passwords, capture clipboard contents, modify web pages, and redirect traffic. Cryptocurrency wallets represent an especially lucrative target because private keys stored in browser memory become accessible.

Users should install extensions only from official stores after verifying developer identity and checking recent reviews for fraud warnings. Limiting extension permissions to minimum required functionality reduces exposure. Cryptocurrency users specifically benefit from dedicated hardware wallets that keep keys offline, eliminating browser-based theft vectors entirely.