A collection of 40 Mozilla Firefox extensions has been discovered stealing cryptocurrency wallet credentials by impersonating popular Web3 products including OKX, Rabby Wallet, and TronLink, according to research published by the Socket Threat Research team. The extensions are part of a broader cluster of 77 browser add-ons that show overlapping source code and infrastructure, in a campaign researchers have named Offside Wallet Theft Factory. The operation has been running since March 2026 and hasn't been linked to any identified threat actor.

Among the 40 confirmed malicious extensions, seven use attacker-controlled Supabase projects as remote switches to deliver phishing or decoy content dynamically, while 15 capture recovery phrases, private keys, and other wallet secrets before sending them out through Cloudflare Workers. Another 13 are modified Rabby Wallet builds that exfiltrate serialized keyrings before local encryption, and the remaining five harvest credentials and clipboard data through hard-coded command and control infrastructure. The 37 related extensions tied to a sports score operation contain deceptive implementations covering football, basketball, NBA, and hockey, and all share a hard-coded credential for API-Sports, a legitimate real-time sports data service, while advertising unrelated features such as password generation, dark mode, VPN access, currency conversion, screenshot capture, and note-taking.

Security researcher Kirill Boychenko stated that "extension-level analysis confirms 40 as malicious," while "another 37 form a coordinated multi-sport score-shell operation" with no confirmed credential- or wallet-stealing payloads in their analyzed builds, but whose "deceptive functionality, shared publishing artifacts, and version histories indicate malicious intent." The Socket team found that historical versions of nine confirmed malicious extensions also used sports-score shells covering football, basketball, NBA, and American football before later versions under the same Firefox IDs were repurposed into wallet-stealing extensions. The other 31 confirmed malicious extensions lack the sports API integration but contain confirmed malicious wallet- or credential-stealing functionality.

The wallet secrets are stolen using two methods: remotely loading a fake wallet page or embedding the functionality directly into the extension itself. In several instances, the add-ons first appeared on the official Firefox extensions marketplace as sports score or utility shells before being converted into wallet-stealing malware under the same Firefox ID. Boychenko explained that "a single successful installation can expose a recovery phrase, private key, or wallet state worth far more than the cost of repeatedly publishing disposable extensions," adding that this economic calculation "helps explain the threat actors' persistence in targeting the Firefox Add-ons ecosystem even when individual extensions are short-lived and ultimately removed." Rotating names and IDs, repurposing existing extension identities, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure make repeated publication cheap and scalable, according to the research. The campaign's longevity demonstrates that attackers can sustain operations by continuously publishing low-cost extensions, waiting for even a small number of installations that could yield high-value wallet credentials. Browser extension marketplaces face an asymmetric challenge where the cost of detection and removal far exceeds the attacker's cost of redeployment, creating conditions that favor persistent, disposable campaigns over one-time sophisticated attacks.