40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Overview
Researchers have discovered 40 malicious Firefox extensions that impersonate popular Web3 products, including OKX, Rabby Wallet, and TronLink, to steal users' cryptocurrency wallet information. The Socket Threat Research team identified these extensions as part of a larger group of 77 browser add-ons sharing similar code and infrastructure. This campaign, named Offside Wallet Theft Factory, poses a significant risk to individuals using these extensions, as they may unknowingly compromise their sensitive wallet credentials. Users of Firefox who have installed these extensions should remove them immediately to protect their assets. The incident serves as a reminder of the ongoing risks associated with browser extensions and the importance of verifying the legitimacy of such tools before installation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Mozilla Firefox extensions, OKX, Rabby Wallet, TronLink
- Action Required: Users should remove the malicious extensions immediately and avoid installing unverified browser add-ons in the future.
- Timeline: Newly disclosed
Original Article Summary
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to
Impact
Mozilla Firefox extensions, OKX, Rabby Wallet, TronLink
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should remove the malicious extensions immediately and avoid installing unverified browser add-ons in the future.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.