threat-intel
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
High
Summary
A group of 40 malicious Firefox extensions, disguised as Web3 products like OKX and Rabby Wallet, are stealing user wallet secrets. These extensions, part of a larger campaign dubbed ‘Offside Wallet Theft Factory,’ have been active since March 2026 and are attributed to no specific threat actor. The campaign utilizes deceptive implementations and shared infrastructure to repeatedly publish malicious extensions, making it a cost-effective operation for threat actors.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
