Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
Firefox was hit by a 77-extension crypto theft campaign linked by shared code, infrastructure, and publishing patterns; 40 extensions were confirmed malicious. Between March 9 and August 3, the add-ons impersonated wallets such as OKX, Rabby Wallet, and TronLink, or disguised themselves as unrelated utilities. About half presented fake wallet interfaces to capture recovery phrases or private keys. Others stole saved credentials, clipboard data, or quietly exfiltrated wallet account data from modified Rabby builds. A second group of 37 extensions looked like password tools, VPNs, converters, or note apps but actually showed live sports scores using a shared credential. Nine malicious extensions first appeared as score apps, then later updates turned them into wallet stealers while keeping the original install history. Anyone who entered a recovery phrase should consider it permanently compromised and move funds to a new wallet.
