Researchers have found a campaign involving malicious Firefox extensions designed to steal cryptocurrency wallet recovery phrases and browser credentials. The activity has reportedly been active since at least March 2026.
Security firm Socket linked 77 Firefox extension identities to the operation. Of those, researchers classified 40 as malicious, while another 37 appeared to be deceptive sports-score add-ons.
Mozilla has removed and blocklisted the identified extensions from its official add-on store.
Fake wallet extensions steal recovery phrases
One extension, called “0KX WEB3,” impersonated the OKX crypto exchange by replacing the letter “O” with a zero. Although it appeared to offer a crypto wallet, researchers found no genuine wallet functionality.
Instead, the add-on used a local notepad as cover while directing users to a remotely loaded page. That page prompted victims to import their wallet and enter a recovery phrase.
Anyone who submitted a seed phrase could have handed attackers full access to the associated crypto wallet. Since recovery phrases can control every asset in a wallet, the damage may be immediate and irreversible.
Sports-score add-ons acted as deceptive cover
The campaign also used harmless-looking sports-score extensions. These add-ons showed real-time scores for sports including football, basketball and hockey.
However, researchers said the extensions shared technical links with the wallet theft operation. Their apparent purpose was to build trust with users and app-store reviewers before being updated or repurposed for malicious activity.
Some extensions advertised unrelated tools, such as password generators, dark-mode features, VPN services, screenshot tools and note-taking apps.
Attackers used remote-controlled phishing pages
The fake wallet extension contained a hardcoded Supabase project address and API key. Supabase is a legitimate cloud platform, but attackers allegedly used the project as a remote control system.
When a victim opened the extension, it retrieved updated content from the remote project. The attackers could then change the phishing destination without issuing a new extension update.
This approach made the malicious Firefox extensions more flexible than a typical infostealer. Rather than stealing data directly from the browser, they guided victims to convincing phishing pages.
Mozilla removed the fraudulent add-ons
Socket reported its findings to Mozilla, which removed and blocklisted the fraudulent extensions. Mozilla has also introduced protections aimed at detecting fake cryptocurrency wallet add-ons.
Still, the campaign highlights the risks linked to browser extensions. An add-on may look legitimate, offer a useful feature and later receive a malicious update.
Users should install extensions only from trusted developers, review permissions carefully and never enter a crypto wallet recovery phrase into a browser extension or website unless they have independently verified it is legitimate.


0 responses to “Malicious Firefox Extensions Target Crypto Wallet Users”