Software supply-chain security firm Socket has identified 40 Firefox add-on identities with confirmed malicious behavior directed at cryptocurrency wallets. The findings include nine tools that originally distributed sports-score updates before switching to crypto-targeting software under the same IDs.
According to an Aug. 19 report, Socket linked 77 total identities to what it provisionally calls the “Offside Wallet Theft Factory,” with 40 containing confirmed malicious functions. The remaining 37 entries were categorized as deceptive or suspicious sports-score shells without analyzed theft payloads. The campaign operated from at least March through August, with Mozilla signing records running from March 9 to Aug. 3, and activity peaking in April and late July.
The 40 confirmed malicious identities utilized various attack methods. Seven acted as remote-controlled phishing loaders, 15 captured recovery phrases or private keys, 13 used modified clones of Rabby wallet software to transmit serialized keyrings before local encryption, and five collected credentials and clipboard data.
Socket reported several campaign add-ons that remained live during analysis, including a remote-controlled phishing add-on named 0KX WEB3 that had seven users. Mozilla subsequently removed it before publication.
Security analysts advise that users whose recovery phrases, private keys, or serialized keyrings reached any of the malicious builds must treat their wallets as compromised. Because uninstalling an add-on cannot revoke an exposed secret, affected individuals are urged to migrate remaining assets to a fresh crypto wallet generated from a new recovery phrase. Users impacted only by the credential and clipboard collection group are advised to change passwords, terminate active sessions, and verify copied destination addresses.
Mozilla confirmed it employs automated risk indicators alongside human review to detect malicious wallet add-ons, advising users to install extensions only via links from official wallet provider websites. As of the report's release, Socket and Mozilla have not identified confirmed victims, specific attributable transactions, or total campaign losses.


