Socket Launches Firefox Extension Scanning After Uncovering 77-Extension Crypto Wallet-Theft Network
Socket added Firefox extension scanning for enterprise customers days after its researchers uncovered 40 malicious extensions stealing crypto wallet secrets.
Editor's Note ·
- Correction:
- The article quotes The Hacker News as saying the extensions were "posing as legitimate Web3 products including OKX, Rabby Wallet, and TronLink." The Hacker News' article actually reads: "masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products." The underlying fact is accurate; the quoted wording was not verbatim.
- Correction:
- The article quotes The Hacker News as saying the add-ons were "converted into wallet-stealing malware under identical Firefox IDs." The Hacker News' article actually reads that the add-ons were "turned into wallet-stealing malware under the same Firefox ID." The underlying fact is accurate; the quoted wording was not verbatim.
Overview
Supply-chain security firm Socket has added Firefox extension scanning to its enterprise product, a launch that follows directly from its own researchers’ discovery of a coordinated network of malicious Firefox add-ons stealing cryptocurrency wallet secrets. According to Socket, the company “now proactively scans every Firefox extension listed in Mozilla’s official addons.mozilla.org directory,” with the new protection available in Experimental status to Socket’s enterprise customers as of the announcement.
What We Know
The product launch was preceded by a threat-research report published a day earlier. Socket researcher Kirill Boychenko detailed a network of “40 malicious extensions that steal wallet secrets or credentials, plus 37 deceptive sports-score shells linked through shared code, infrastructure, publishing artifacts, and version histories” — 77 extensions in total. Socket is “provisionally tracking this campaign as ‘Offside Wallet Theft Factory,’ reflecting both the sports-score shells that helped expose the broader ecosystem and its factory-like production of cloned extensions designed to steal cryptocurrency wallet secrets,” according to the report.
The findings were independently corroborated by other outlets. The Hacker News reported that the 40 malicious extensions were “posing as legitimate Web3 products including OKX, Rabby Wallet, and TronLink,” and quoted Boychenko confirming the split: “Extension-level analysis confirms 40 as malicious. Another 37 form a coordinated multi-sport score-shell operation.” SC Media separately confirmed that “Socket researchers identified 40 malicious extensions and 37 others disguised as unrelated utilities, all linked through shared code, infrastructure, and publishing artifacts.”
Socket’s research breaks down the theft techniques used across the 40 malicious extensions. Seven “use threat actor-controlled Supabase projects as remote switches for phishing content,” letting operators toggle between benign and malicious behavior without republishing the extension, Socket said. Fifteen “capture recovery phrases, private keys, or other wallet secrets and exfiltrate them through Cloudflare Workers,” while 13 “modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption.” A further five “steal credentials and clipboard data through hardcoded command and control (C2) infrastructure,” which Socket identified as the IP address 77[.]91[.]100[.]175.
According to Socket’s report, the campaign has been running since at least March 2026, with Mozilla signing records for the extensions spanning “March 9 to August 3, with activity peaking in April and late July.” Some of the extensions began their life on the Firefox marketplace as ordinary sports-score utilities before later versions, published under the same extension identities, converted them into wallet-stealing malware — a pattern The Hacker News also described, noting the add-ons were “converted into wallet-stealing malware under identical Firefox IDs.” Socket said it “reported extensions that remained live during the investigation to Mozilla’s security team,” adding: “We appreciate the vigilance and responsiveness of Mozilla’s Add-ons Operations team.”
The new enterprise scanning product that followed this research covers a large surface: Socket says “Mozilla’s public API lists 97,100 Firefox-compatible extensions” at the time of its announcement. The product’s stated capabilities span four categories — visibility, threat detection, update monitoring, and “ecosystem context” — with detection aimed at “malware, credential and clipboard theft, data exfiltration, remote code and content loading,” according to Socket’s announcement.
What We Don’t Know
Neither Socket nor the outlets covering the research have publicly stated whether Mozilla has removed all 77 identified extensions from its store, or attributed the campaign to a specific threat actor or group. SC Media noted that users who installed the malicious extensions “should assume their wallet information is compromised and move funds to a new wallet, change passwords, and review browser activity,” but no outlet has published a count of how many users were affected. Socket’s enterprise scanning product remains in Experimental status and is not yet available outside its enterprise customer base.