A group of 40 Mozilla Firefox extensions has been identified as malicious tools designed to steal cryptocurrency wallet information while posing as legitimate Web3 products, including OKX, Rabby Wallet and TronLink. The discovery highlights continued risks for users relying on browser extensions to manage digital assets.
The extensions were identified by the Socket Threat Research team as part of a wider collection of 77 browser add-ons with overlapping source code and infrastructure. Researchers have dubbed the campaign the Offside Wallet Theft Factory and believe the operation has been active since March 2026. No known cybercrime group or threat actor has been publicly linked to the activity.
Security researchers determined that 40 of the extensions contained confirmed malicious functionality. The remaining 37 were associated with a coordinated sports-score operation and did not contain confirmed wallet or credential-stealing payloads in the analyzed versions. However, their deceptive behavior, shared publishing characteristics, and version histories were assessed as indicators of malicious intent.
Researchers found that 15 of the confirmed malicious extensions can capture recovery phrases, private keys, and other wallet secrets before sending the stolen information through Cloudflare Workers.
Multiple Techniques Used to Steal Wallet Credentials
The malicious extensions employ several techniques to obtain sensitive cryptocurrency information. Seven of the identified extensions use Supabase projects controlled by the attackers as remote switches, allowing them to dynamically deliver phishing pages or decoy content.
Another 15 extensions directly collect recovery phrases, private keys, and other wallet-related secrets before exfiltrating the information through Cloudflare Workers. Researchers also identified 13 modified versions of Rabby Wallet that can extract serialized keyrings before the information is encrypted locally.
The remaining five extensions use hard-coded command-and-control infrastructure to collect credentials and clipboard information. Such capabilities could expose users to theft of wallet addresses, authentication data, and other sensitive information stored or copied through the browser.
The wallet-stealing mechanisms generally operate in two ways. Some extensions remotely load fraudulent wallet pages designed to trick users into entering their credentials or recovery information. Others contain the malicious functionality directly within their code.
Researchers also found evidence that some extensions initially appeared in the official Firefox marketplace as sports-score tools or general utilities before being transformed into wallet-stealing software while retaining the same Firefox extension IDs.
Sports Utilities Used as a Deceptive Cover
The other 37 extensions were linked to a separate sports-score operation involving deceptive implementations related to football, basketball, NBA, and hockey. These extensions contained a hard-coded credential associated with API-Sports, a legitimate service providing real-time sports information.
Despite their sports-related components, the extensions were promoted as offering unrelated tools such as password generation, dark mode, VPN functionality, currency conversion, screenshot capture, and note-taking.
Historical versions of nine confirmed malicious identities were also found to have used sports-score shells before later versions associated with the same Firefox IDs were repurposed for cryptocurrency wallet theft. Researchers said the other 31 confirmed malicious identities did not use the sports API but contained verified wallet- or credential-stealing capabilities.
Among the identified extension names were Safe-Themes – Browser Extension, Rabbit For Desktop, ℞ab␢y Wa❘Iet, Rabb-Walӏet CryptoPortfolio, RABB-Walӏet Web3 & EVM and Rabbit/WALLET – EVM.
The campaign demonstrates how attackers can reuse extension identities, rotate names, clone code and distribute malicious functions across browser extensions, remote pages, and cloud infrastructure to make repeated attacks inexpensive and scalable.
Firefox Users Face Continuing Extension Risks
The researchers said the economics of browser-extension attacks could encourage continued targeting of cryptocurrency users. A single successful installation can potentially expose a recovery phrase, private key, or wallet state with a value far exceeding the relatively low cost of publishing disposable extensions.
The campaign also illustrates the difficulty of identifying malicious extensions solely by their initial marketplace descriptions. Attackers can present an add-on as a harmless utility, gradually alter its functionality and use existing identities to avoid the cost of starting from scratch.
For cryptocurrency users, the findings reinforce the importance of carefully checking extension authenticity, limiting unnecessary browser permissions and avoiding wallet installations that cannot be independently verified.
The findings indicate that extension-based wallet attacks are becoming increasingly adaptable, with attackers combining deceptive marketplace listings, repurposed identities and cloud-based infrastructure to target valuable cryptocurrency credentials.







