Socket links 77 Firefox extensions to Offside Wallet Theft Factory

Security firm Socket has identified 40 Firefox add-ons with confirmed cryptocurrency wallet-theft behavior among 77 interconnected extensions it named the Offside Wallet Theft Factory. Nine of the malicious add-ons had earlier shipped as sports-score tools under the same IDs before updates introduced hostile code, while 37 related extensions posed as password generators, dark-mode toggles, VPN tools and similar utilities but displayed live sports scores using one shared sports-data credential. Attack paths among the 40 included seven Supabase-backed remote phishing loaders impersonating OKX, Rabby Wallet and TronLink—including the counterfeit 0KX WEB3 listing—15 extensions that harvested recovery phrases and private keys and sent them to attacker-controlled Cloudflare Workers, 13 modified Rabby builds that exfiltrated unencrypted keychain data before local encryption, and five that stole credentials and clipboard contents via hardcoded servers. Mozilla signing records for analyzed versions ran from March 9 through August 3; several add-ons remained live when reported, and 0KX WEB3 was removed before publication. Socket expanded Firefox extension monitoring on August 20 to more than 97,000 store listings and warned that uninstalling a compromised add-on does not revoke secrets already transmitted, so exposed users should move funds to a new wallet. Socket documented infrastructure and theft capability but identified no confirmed victims or loss total.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.