Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mozilla Firefox wallet-stealing extensions masquerading as Web3 products

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

A 40-extension Mozilla Firefox malware set is stealing cryptocurrency wallet secrets by impersonating OKX, Rabby Wallet, and TronLink, creating direct theft risk for extension users. The malicious set sits inside a broader cluster of 77 browser add-ons linked by shared code and infrastructure, and the operation has been active since March 2026. The extensions steal recovery phrases, private keys, serialized keyrings, credentials, and clipboard data using fake wallet pages, embedded theft logic, Cloudflare Workers, and hard-coded C2.

Related Happenings

PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS

Malware Activity
H score29 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...

KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking

Technical Analysis
H score24 First: 14.07.2026 14:55 Last: 14.07.2026 14:55 Sources 1

About this happening: KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...

Silent Swap browser-extension clipboard clipper

Malware Activity
H score36 First: 30.06.2026 18:40 Last: 30.06.2026 18:40 Sources 1

About this happening: The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-con...

StegoAd malicious Edge extension operation

Malware Activity
H score19 First: 29.06.2026 11:32 Last: 29.06.2026 11:32 Sources 1

About this happening: The StegoAd operation was removed from the Edge Add-ons store after hiding payloads in images and fonts, stealing credentials, and driving ad fraud across installs tha...

Chrome Web Store malicious extensions coordinated campaign using shared C2

Campaign
H score38 First: 14.04.2026 23:33 Last: 14.04.2026 23:33 Sources 1

About this happening: A coordinated Chrome Web Store extension operation is stealing Google OAuth2 Bearer tokens, deploying backdoors, and running ad fraud across more than 100 malici...

Timeline

  1. 20.08.2026 11:42 2 articles · 3h ago

    Socket finds 40 Firefox extensions stealing cryptocurrency wallet secrets

    Initial Disclosure

    Socket Threat Research found 40 malicious Mozilla Firefox extensions within a broader set of 77 browser add-ons that impersonated OKX, Rabby Wallet, TronLink, and other Web3 products to steal cryptocurrency wallet secrets. The campaign, Offside Wallet Theft Factory, used fake wallet pages, built-in theft logic, threat actor-controlled Supabase projects, Cloudflare Workers, and hard-coded C2, and some extensions first appeared as sports score or utility shells before being repurposed under the same Firefox ID. The activity is believed to have been active since March 2026, and the activity has not been attributed to any known threat actor or group.

    Show sources