At a Glance
| Malware family | Offside Wallet Theft Factory (campaign of cloned wallet-stealing extensions) |
| Threat actor | Unattributed; a common publishing pipeline or closely related actors (under investigation) |
| Targets | Firefox users of Web3 and crypto wallets (OKX, Rabby, TronLink and others) |
| Delivery vector | Malicious Firefox Add-ons impersonating wallets and disguised utilities |
| Capabilities | Recovery-phrase and private-key theft, keyring exfiltration, credential and clipboard theft |
| Source | Socket Threat Research |
TL;DR
Socket is tracking 77 malicious Firefox extensions built to steal crypto wallet secrets. Researchers confirmed 40 as malicious and flagged 37 more as deceptive shells. The malicious Firefox extensions impersonate wallets like OKX and Rabby to grab recovery phrases, keys, and credentials.
Delivery
The extensions arrive through the Firefox Add-ons store. Many pose as crypto wallets, copying real branding and screenshots. Others hide as themes, VPNs, or note-taking tools.
The campaign has run since at least March 2026 and continued into August. Mozilla signing records for the first 59 versions span March 9 to August 3. Several extensions were still live when Socket reported them.
Infection Chain
The operation uses several models, not one. Socket groups them by how each steals wallet secrets.
Remote Phishing Loaders
Seven extensions act as remote-controlled phishing shells. One, called 0KX WEB3, carries a decoy notepad and no real wallet code. Socket concludes it is “better classified as a remote-controlled phishing delivery extension than a conventional infostealer.”
These loaders pull a URL from a threat actor-controlled Supabase project. A single value flips the extension between a decoy and a live phishing page. The fake page then asks victims to import a wallet using a recovery phrase.
Modified Rabby Wallet Builds
Another cluster hides altered Rabby wallet code. Thirteen extensions exfiltrate serialized keyring data before local encryption runs. The theft hooks a normal save routine, so the wallet still works.
As Socket puts it, the code lets the wallet “behave as expected while silently disclosing its most sensitive secret.” Removing the add-on stops new theft but cannot recover exposed data.
Counterfeit Wallet Forms
Fifteen extensions embed the theft logic directly. They show fake wallet-import screens for Portal, OKX, or generic Web3 tools. Submitted recovery phrases and keys go to attacker-run Cloudflare Worker deployments.
Command-and-Control and Exfiltration
The campaign abuses trusted cloud services to move stolen data. Supabase acts as a remote switch for phishing content. Cloudflare Workers receive stolen recovery phrases and keys.
A separate cluster of five extensions steals credentials and clipboard contents. That data flows to a hardcoded command-and-control server over plain HTTP. The clipboard capture is split into numbered chunks so the server can rebuild large content.
Socket warns that copied text can expose a lot. Depending on activity, it may include “passwords, authentication material, cryptocurrency addresses, private keys, or other sensitive information.” A shared campaign token and reused code link many variants together.
Attribution
Attribution is not settled. Socket states the evidence “does not establish that a single threat actor controls every extension.” Russian-language code comments appear in some builds, but the team keeps its attribution cautious.
Detection and Defense
Wallet users can lower the risk with a few habits. Never enter a recovery phrase or private key into a browser extension popup. Treat any extension that asks for wallet secrets as hostile.
Install wallets only from the vendor’s official source. Watch for look-alike names that swap letters for digits or homoglyphs. For the full technical breakdown and indicators, read the Socket Threat Research report.
Defenders should note one lesson from this campaign. Low permission requests do not mean low risk. An extension needs few privileges when its job is to show a remote page and coax out secrets. Hardware wallets, which keep keys off the browser, add a strong layer of protection.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!