Socket Links 77 Firefox Extensions to Crypto Wallet and Credential Theft

Summary
Socket traced 77 linked Firefox extensions to a campaign involving wallet-secret theft, credential and clipboard collection, and deceptive sports-score shells. The research confirmed malicious payloads in 40 extensions; Mozilla removed one reported extension.
Key points
- Socket linked 77 Firefox extension identities through reused code, infrastructure, publishing artifacts, and version histories; 40 were confirmed malicious, while 37 deceptive sports-score shells had no confirmed theft payload in the analyzed builds.
- Some extensions use Supabase-controlled remote pages to phish for recovery phrases or private keys; others package counterfeit wallet interfaces or modified wallet code that sends secrets to Cloudflare Workers.
- Thirteen modified Rabby-derived extensions exfiltrate serialized keyrings before local encryption, while five extensions collect credentials and clipboard contents and send them to hardcoded command-and-control infrastructure.
- Historical versions show nine confirmed malicious identities previously distributed sports-score shells before being repurposed as wallet-stealing extensions.
- The campaign was active from at least March through August 2026. Socket reported extensions still live during its investigation to Mozilla; the 0KX WEB3 extension was removed before publication.
- Socket advises evaluating extension code, remote-content behavior, version history, infrastructure, and publishing artifacts—not permissions alone. Exposed recovery phrases or private keys should be treated as permanently compromised.
Article Details
- Attack Vectors
- Deceptive Firefox extensions impersonated cryptocurrency wallets or advertised unrelated utility functions.
- Seven extensions used Supabase projects to select remote content, allowing a phishing page to appear in an extension popup or an installation-time window without republishing the extension.
- Fifteen extensions captured recovery phrases or private keys through modified wallet code or counterfeit wallet-import interfaces and sent them to Cloudflare Worker deployments.
- Thirteen Rabby-derived extensions transmitted serialized keyrings before local encryption while allowing the wallet's normal persistence workflow to continue.
- Five extensions collected credentials and clipboard contents and transmitted them to a hardcoded C2 server; clipboard contents were divided into numbered chunks.
- Historical versions of nine confirmed malicious extension identities were sports-score shells before later versions under the same Firefox IDs became wallet-stealing extensions.
- Defensive Notes
- Do not treat low extension permission requirements as proof of safety: some extensions relied on users entering secrets into attacker-controlled interfaces.
- Assess extension code similarity, remote-content behavior, version changes, Firefox IDs, infrastructure, signing history, and cross-package artifacts together.
- Re-evaluate extensions after updates, particularly when an existing identity changes functionality.
- Treat exposed recovery phrases and private keys as permanently compromised even after removing an extension.
- API-Sports traffic alone is insufficient for detection or attribution; the article recommends considering it alongside package and publishing evidence.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 77[.]91[.]100[.]175 | Hardcoded C2 address used by five credential- and clipboard-stealing extensions. |
| SHA256 | 08b7b064fa9a41b06774315d944ffddff705ab727222a0c3bcac64a77553bf2f | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 0e163cde2337fbc11232b548e301dea746b764b898e0decbfcc7940248d4f092 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 1381fc82afd785cb0dfc2cf511ed49d4487cb9cd4edee9f741b38710624a1bd0 | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | 1429f5134b5acf5077a18cf805bc905393524debad75f70a942ec30608f49088 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 14a2da218e41d3854e731d02f8a444a1b9712ba2788d57b5a76c18737bd559ae | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 172b7618498d1c9da6ff6aecc8f680d2b3956b7c86d80fbc060e0adae8f38ebf | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 1753fa38657c6c0d23ff7ca12a768a1b23ac3d8f3896c746ae2bdc7538c03009 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 1857acb44d3e577645f7ca64e76a14609d960c6a6efa56ea00c28ac43df4463f | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 1b3634aec03d85d9e7463e363b6664e9105f17badfa5f1cf737b1623267ae631 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 1cbe34e76e4ebb1e8b185f67e8f5bc507427af7692512b9e6a93ec6051685d95 | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | 252119fc48ad93b0c930d7a62fb49420cf8986716539e4e9d4d5c1bad700d435 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 26427220b9965e22deca0e617657c2c65b78f750183355d1265c147818367bd7 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 2a0856637d0e3850b153713ef34d1963b6d6b06acaa1e4fbdc6fa305483987ca | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | 2b0d50aa0edf4f65e21b015fee169d68dc870a89d242836ccb3c7cef84db04c4 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 2fb5b89c0889a8bde90845de2db13161f6d8845fa5dbc56bfa474f800c664d9e | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 31dc33e75aa2a9e64eac98467c5a516201e208d68ffe10d07800350ce1a44197 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 36b8cbed79b91b92e84eb01d61c57c8972cacc68a3d6a3629e2a2b25a59ee11d | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 39827e214c31dbbf0ce20a40ee019cca2d96d621bf90dac4edc8b85a86311d09 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 3c0f0413ca6326bd0107d532aec4daad7feec663d072f7c992682fb702b64cce | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 3e4cd172c21c0c0d72c762fe84f07a9eb8f7c82f15add36bdf934ee42accf776 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 3f52fcb79e2b8e255030b1270f22618417e622e65406cf6e3e715e2f0a80b9e3 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 3f73e8af9eb2d664be44e07955253a59c5dab684c645ab648f36c2cbccddcdb3 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 40f6611eacbcf10f6260f91caeb4a2223313f466340f3ea9d47d6e34ee8b889a | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 46305296e0675147c7b4ceacc7d5e45dd44d5d2242c0c3e02b444931b3e1564b | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 46c40d3cefb10a9fd1dfeb03ff1dc550674d391bdf05c0294257809d51c254a8 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 4d0912d575087dab5f468214a2fd259bc386472a8b2b93b6e2441cde4bd941cb | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 5328d5e600d1de7e4ffe8bd38dd1fdf22f1226b21c4d77db10aca7c9ce31c2a8 | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | 547a878083e4e3c39c240f27e9caaa190ef04661f46468234987980d907d9834 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 54d57acdd0557e22f9dd1350ac1bf1f536dd5859394b39cf9ba586b3d2339f05 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 56a6dbde57aab6ab2f4f1d5af1d6fbc3e775a600026382e56df7ef5363c50d4d | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 57d78328f2cd02e91e511fbee80fc2dc43368adf0c84fac4cc0bbbce3fad5d8a | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 5a7227dbf8e5c5c73f11c7df221c080252b337cb96b21f462d5ef17525f00f16 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 5bebc15d404c4f7314f4e4cd7e24aff1178de124374128bc845a034e3f6c9853 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 5c8121bd3394c4ea6d273a6936aeaa7d30aa748a978b440d7144819522813153 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 5dcbce26e54dd44d0b932e23f1a741298d4e35487d1868b469518f903e577a7a | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | 5dd33e0737e82b2e324dc4c04ce862da185153d54705697cfd0181e848bf35d4 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 61659464d6ac002757b51c276f22cd3fff25089c1dc257c0b81309bf49aba7c0 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 61a19cab5c7bbcf5ded1c8b6a05d586ecbe03afc055c132049226f86f5127b3d | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 6408b6a2c4000e74cde94d3ce31ada5e024d80782199e8010d6ef482686e687b | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 66150abf5072f0d02118648d072afecdc8bac1d224dbc569836a65398d48e98d | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 68b25a9761e04f3c68af6d94e2ad3ca259ebbaf06e90798d6c2613ddc3e434c4 | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | 6a3c00936b7f62652eb4970b2bd3bb895fdd9ec1ebae1dab19f0c50cfbdc6b4c | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 6db5ea393b1618259fee5a2ca7467be47ea025255d2ab45a78b76e23e4e0b59e | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 708291399f6d98529e02a1d0100084abfe1e09d3fb7d8fefad744f1e7f439420 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 716cc37e2019a92ab1970d74e3ee962cafb4eef97fbd55353f15a34c8e0c2a30 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 71f74a903b12fdaa1cb7683599b7956602768f23934578171f6453fdee7b3eac | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 790c869021cf7584271c73cb4eac8a094595e7225f69acc1a4b145903b2bc1c2 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 793a2d26dc9781bbf3e61db85009626f7de9edc19bddc349f29b4cf74d1b184e | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 7d950ad43d7e83f8f84a2033f88349d384972a9b69cde3cc2ca1ee28e1be94ed | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 8590d1a22fdf42a363fe41fe6dc2cb03e616cc6d413f63d2ade9fd3ab54f1c83 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 88d5b16c767e2527c14d2ae25dca6f4fe19f69517d0e00a2f26be055c575e3fe | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 894109c97ccb215f523e41bc968ffa7716959c62c7c3f625cf4c03d50e899072 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 894398430972f91db2f1916f9fbe28b7319cb0e7d0e91a51e764fda5e7d1e8c9 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 8cec7990d4bc5e45034796fc63c63ba16781ac4303925ed1e80036668a9fe48e | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 918332da18e0f26378ee84408be13930da2d66cd80153cf18a5aa3d6d0cb2271 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | 96be1669cbc95c35a5448311fb808cf915ea89cdee983ae905f903f9fcb5bb6d | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 96d03bb2b8a59db38200278dc17fbafc14c55795a126068f3e7a3fc7a749730f | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | 9c6f173418245a953d5fc3e9ec69f09b7aee8563127042a995ad172de9cdb88d | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | a2eba930f94306f2f4f27b74351c1ce0a75210bac51d9efa09c71d69d3cb9990 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | a3a31d7338b047de63b5c92a8d697292a26b0fccb4797918462139b8767d97f8 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | a3d9369e666aeb7230956bd6dd97b7337b829c5ae5139171e90593de17dc9b08 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | aa9d8f30bd6e0633af5bb0fa16ed2e87fcd22e87725c48a5c96884465e262a28 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | acf6f82916e78b2e5326fd16d6c97206532305cf5d68ea21e1a30537bffd26c0 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | aeb6240b2f40a177999f68ae6fc88e511669d501aa298a433b05bafa89210685 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | af69e15e02d4c2850a6ed26e9d7d1152e16e2d7d01695bbf3b3840adf0b6bee5 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | b44c7cd048bbe7f165fd28a755765c978373ee6761b6ae306ba57e9e1895536b | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | b65143df86edd60625fcbc0fcb396ef02baae6e731c1993e70873563e5a1524c | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | b8b5ad5c18626e11bf4960a8245539334367be6655bd4c21140bb27c82efb679 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | bdcb3789c063a06369ff73906d7776846a163d6c60ff8dbcc549bc2dfe5ea382 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | bee995e253092c8c8edfa4104799adbe40967596dfdb28a5668390aea40d0883 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | c7435c1659b6e0dc83487d03b3389ec22bb7e435c9b4c85a81f6c6504466060b | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | d5c5331b82771fe91213c246d076ad6d08157b5390fabb4a1d7209b1a5db15dd | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | d671be66381149dc7efb9c77f081fc1e3410cbf2447fe7652b77b08f895503d8 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | e0373ebe9eec5ec6734bbbd012fc9874c78b35f7cd444e9df1461f8d03d3b0d0 | Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets. |
| SHA256 | e335066fb09d0d9d0e5fd55b946d430071fb6f157bdb9b38e7f50714178a51eb | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | e4c3a669362e8b456b1d6c8e6df7da2a9605a42d710d0cc951342b7ac0cb9d72 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | e4f351a6d6a8249691eec07223c74ca9c8708522919e1626baef705acb1ad87d | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | e7ef1558ecba876e2786e5f281d5551e2ab161c52f3443e5c81f4ffd0ba17d5b | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | eb4718f52161d2262e9aa83b4b561fa475486f5183600376d002be3333823787 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | ed63c3a14b51915863bbc443f169dccb73baebdc4e553cdfe18ef1a68b72ffb2 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | edcdbcdbea729fb11cbb0a353c3a9025e5a29de48fcd86e3948df738bf82b2aa | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | eeb1969d0c8b250976ec220f40236ddd7eb6863556379d17e1dd4078b5531751 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | eec0638729b096e0d0f93173be9b105b15371b76c167dfa89e5a882ee290d9cb | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | f0d262d1b1e446ee1a6db37b0301b9e2ab160269b193920212d55d7dfb231fe1 | Package hash listed for a confirmed malicious Firefox extension. |
| SHA256 | f70febe6549d1439cf1f140cae18f13e7150ffe4ca31e3e00656b878a0153366 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | fc74265e10942ee96726c7cce9b642cc7492835cb4eb43d4451bd2aab13e1ec8 | Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build. |
| SHA256 | fd67f4a3c8993b1ce6aecf0cc8902e6a8535a6ef56c0bad42d7e936d0a17e060 | Package hash listed for a confirmed malicious Firefox extension. |
| URL | hxxp[:]//77[.]91[.]100[.]175/html/app[.]php | C2 URL receiving captured credentials. |
| URL | hxxp[:]//77[.]91[.]100[.]175/html/continue[.]php | C2 URL receiving chunked clipboard contents. |
| URL | hxxp[:]//alt[.]e-wl[.]com:9000/hook/alt | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//consol[.]e-wl[.]com:9000/hook/cosomid | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//firebase[.]e-wl[.]com:9000/hook/see | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//id[.]gemachriverdale[.]org:9000/hook/pastre | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//id[.]gemachriverdale[.]org:9000/hook/ptvve | HTTP endpoint used to collect serialized wallet keyrings before local encryption. |
| URL | hxxp[:]//id[.]gemachriverdale[.]org:9000/hook/rra | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//mapid[.]e-wl[.]com:9000/hook/mapid | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//ommid[.]e-wl[.]com:9000/hook/ommid | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//pch[.]e-wl[.]com:9000/hook/pch | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//rest[.]e-wl[.]com:9000/hook/rest | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//temple[.]e-wl[.]com:9000/hook/temple | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//typec[.]e-wl[.]com:9000/hook/typo | Serialized-keyring exfiltration endpoint. |
| URL | hxxp[:]//vala[.]e-wl[.]com:9000/hook/value | Serialized-keyring exfiltration endpoint. |
| URL | hxxps[:]//acrfruxtmulgvyvtbwgq[.]supabase[.]co | Campaign-embedded Supabase project URL used as a remote-control artifact. |
| URL | hxxps[:]//dry-bush-5408[.]animalrescueeducationcenter-org[.]workers[.]dev/ | Threat actor-controlled Cloudflare Worker endpoint receiving stolen recovery phrases. |
| URL | hxxps[:]//dry-bush-5408[.]animalrescueeducationcenter-org[.]workers[.]dev/?a=login&s=EQOx7EIPZSNi&k=login&w=<mnemonic> | Article's observed recovery-phrase exfiltration request pattern. |
| URL | hxxps[:]//efiukydskwkeatexavdp[.]supabase[.]co | Campaign-embedded Supabase project URL used as a remote-control artifact. |
| URL | hxxps[:]//kyfyvuwifdukctqyggto[.]supabase[.]co | Campaign-embedded Supabase project URL used as a remote-control artifact. |
| URL | hxxps[:]//mzghdnikguesdamuxjbm[.]supabase[.]co | Campaign-embedded Supabase project URL used as a remote-control artifact. |
| URL | hxxps[:]//nxsixihozitybwrbahiu[.]supabase[.]co | Campaign-embedded Supabase project URL used as a remote-control artifact. |
| URL | hxxps[:]//portal-web3-extension-welcome[.]pages[.]dev/home | Threat actor-controlled wallet-phishing page loaded by the remote-controlled extension. |
| URL | hxxps[:]//quiet-thunder-ade3[.]bankoganger[.]workers[.]dev/ | Cloudflare Worker endpoint identified as campaign exfiltration infrastructure. |
| URL | hxxps[:]//vgksucdjccsojzuhckzk[.]supabase[.]co | Supabase project URL embedded in the malicious Rabbit For Desktop remote loader. |
| URL | hxxps[:]//vnigkfdwwyphfafficet[.]supabase[.]co | Residual Supabase configuration embedded in the fake OKX extension. |
| URL | hxxps[:]//winter-smoke-a612[.]icy-star-f45c[.]workers[.]dev/ | Cloudflare Worker endpoint receiving stolen wallet secrets. |
| URL | hxxps[:]//winter-smoke-a612[.]icy-star-f45c[.]workers[.]dev/?a=login&s=EQOx7EIPZSNi&k=login&w=<mnemonic> | Article's observed recovery-phrase exfiltration request pattern. |
| URL | hxxps[:]//winter-waterfall-0606[.]rihaniomar21[.]workers[.]dev/ | Cloudflare Worker endpoint receiving secrets from a counterfeit wallet extension. |
| URL | hxxps[:]//winter-waterfall-0606[.]rihaniomar21[.]workers[.]dev/?w1=<mnemonic> | Article's observed wallet-secret exfiltration request pattern. |
| URL | hxxps[:]//winter-waterfall-0606[.]rihaniomar21[.]workers[.]dev/?w1=<wallet_secret> | Counterfeit OKX wallet's described secret-exfiltration request pattern. |
| URL | hxxps[:]//yvqmtnmeivrcyomyeouz[.]supabase[.]co | Campaign-embedded Supabase project URL used as a remote-control artifact. |
MITRE ATT&CK
T1005 · Data from Local SystemModified Rabby-derived extensions obtained serialized local keyring data during the wallet persistence workflow.T1020 · Automated ExfiltrationEmbedded extension logic automatically transmitted captured recovery phrases, keyrings, credentials, or clipboard contents.T1030 · Data Transfer Size LimitsClipboard-stealing extensions split captured contents into numbered chunks for transmission.T1036.005 · Match Legitimate Resource Name or LocationExtensions used wallet-like names, branding, and visually similar characters to resemble legitimate wallet products.T1041 · Exfiltration Over C2 ChannelFive credential- and clipboard-stealing extensions sent collected data to their hardcoded C2 server.T1056.002 · GUI Input CaptureCounterfeit wallet-import interfaces prompted victims to type recovery phrases or private keys.T1059.007 · JavaScriptJavaScript in extension packages queried Supabase for remote content and implemented wallet-secret or clipboard collection.T1071.001 · Web ProtocolsExtensions used HTTP or HTTPS requests to query remote controllers and transmit stolen secrets to collection endpoints.T1102.001 · Dead Drop ResolverRemote-loader extensions queried a Supabase table for the latest content value to obtain a URL for remotely selected phishing content.T1115 · Clipboard DataFive extensions monitored and collected clipboard contents.T1176.001 · Browser ExtensionsThe operation published malicious and deceptive Firefox browser extensions, including extensions later repurposed under existing IDs.T1204 · User ExecutionWallet-phishing workflows depended on victims installing extensions and entering recovery phrases or private keys.
Vendors
API-Sportsspanning football, basketball, NBA, and hockey, sharing a hardcoded credential for legitimate API-Sports services while advertising unrelated functions such as password generation, dark mode, VPN access,Cloudflarecontent. 15 capture recovery phrases, private keys, or other wallet secrets and exfiltrate them through Cloudflare Workers. 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption, whileMozillaThe campaign has operated since at least March 2026 and continued into August. Mozilla signing records for the original 59 analyzed versions span March 9 to August 3, with activity peaking in April and late July. OurSupabaseimpersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases, private keys, or other
Products
Cloudflare Pagesit in a separate window after installation or update. The destination, hosted through the legitimate Cloudflare Pages service, presents a polished Web3 interface with Create wallet and Import wallet options.Cloudflare Workers15 capture recovery phrases, private keys, or other wallet secrets and exfiltrate them through Cloudflare Workers. 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption, while fiveFirefox Add-onsIts Firefox Add-ons listing used OKX-style branding and screenshots, described the extension as a universal Web3 wallet, and claimed that it collected no data. The name substitutes a zero for the letter “O” in OKX,Mozilla FirefoxThe Socket Threat Research team is tracking 77 Firefox extension identities linked through code reuse, cloned extensions, deceptive marketplace descriptions, author-selected add-on ID patterns and domain-like suffixes,OKXThe malicious extensions impersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases,Rabby WalletThe malicious extensions impersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases,Supabaseimpersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases, private keys, or otherTronLinkThe malicious extensions impersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases,