40 malicious Firefox add-ons targeted crypto wallets, and 9 began as sports-score tools

Binance
Changelly


Software supply-chain security firm Socket found 40 Firefox add-on identities with confirmed malicious behavior, including draining crypto, including nine that had previously distributed sports-score tools under the same IDs.

Anyone whose recovery phrase, private key, or wallet keyring reached one of the malicious versions must treat that wallet as compromised because uninstalling the add-on cannot revoke an exposed secret.

The Aug. 19 report linked 77 identities to what Socket provisionally calls the “Offside Wallet Theft Factory,” with 40 containing confirmed malicious behavior. The other 37 were deceptive or suspicious sports-score shells whose analyzed versions contained no confirmed theft payload.

The campaign operated from at least March into August. Mozilla signing records for the original 59 versions analyzed by Socket ran from March 9 through Aug. 3, with activity clustering in April and late July.

itrust
Infographic showing 77 linked Firefox add-on IDs split into 40 malicious and 37 deceptive sports shells, with nine IDs repurposed and separate remediation for crypto wallet-secret and credential exposure.Infographic showing 77 linked Firefox add-on IDs split into 40 malicious and 37 deceptive sports shells, with nine IDs repurposed and separate remediation for crypto wallet-secret and credential exposure.
Infographic showing 77 Firefox wallet extension IDs, including 40 confirmed malicious extensions using phishing, credential theft, and wallet-draining techniques.

Socket’s version histories show that the nine affected IDs were: