Socket Links 77 Firefox Extensions to Crypto Wallet and Credential Theft

· Original article ↗

Summary

Socket traced 77 linked Firefox extensions to a campaign involving wallet-secret theft, credential and clipboard collection, and deceptive sports-score shells. The research confirmed malicious payloads in 40 extensions; Mozilla removed one reported extension.

Key points

  • Socket linked 77 Firefox extension identities through reused code, infrastructure, publishing artifacts, and version histories; 40 were confirmed malicious, while 37 deceptive sports-score shells had no confirmed theft payload in the analyzed builds.
  • Some extensions use Supabase-controlled remote pages to phish for recovery phrases or private keys; others package counterfeit wallet interfaces or modified wallet code that sends secrets to Cloudflare Workers.
  • Thirteen modified Rabby-derived extensions exfiltrate serialized keyrings before local encryption, while five extensions collect credentials and clipboard contents and send them to hardcoded command-and-control infrastructure.
  • Historical versions show nine confirmed malicious identities previously distributed sports-score shells before being repurposed as wallet-stealing extensions.
  • The campaign was active from at least March through August 2026. Socket reported extensions still live during its investigation to Mozilla; the 0KX WEB3 extension was removed before publication.
  • Socket advises evaluating extension code, remote-content behavior, version history, infrastructure, and publishing artifacts—not permissions alone. Exposed recovery phrases or private keys should be treated as permanently compromised.

Article Details

Attack Vectors
  • Deceptive Firefox extensions impersonated cryptocurrency wallets or advertised unrelated utility functions.
  • Seven extensions used Supabase projects to select remote content, allowing a phishing page to appear in an extension popup or an installation-time window without republishing the extension.
  • Fifteen extensions captured recovery phrases or private keys through modified wallet code or counterfeit wallet-import interfaces and sent them to Cloudflare Worker deployments.
  • Thirteen Rabby-derived extensions transmitted serialized keyrings before local encryption while allowing the wallet's normal persistence workflow to continue.
  • Five extensions collected credentials and clipboard contents and transmitted them to a hardcoded C2 server; clipboard contents were divided into numbered chunks.
  • Historical versions of nine confirmed malicious extension identities were sports-score shells before later versions under the same Firefox IDs became wallet-stealing extensions.
Defensive Notes
  • Do not treat low extension permission requirements as proof of safety: some extensions relied on users entering secrets into attacker-controlled interfaces.
  • Assess extension code similarity, remote-content behavior, version changes, Firefox IDs, infrastructure, signing history, and cross-package artifacts together.
  • Re-evaluate extensions after updates, particularly when an existing identity changes functionality.
  • Treat exposed recovery phrases and private keys as permanently compromised even after removing an extension.
  • API-Sports traffic alone is insufficient for detection or attribution; the article recommends considering it alongside package and publishing evidence.

Indicators of compromise

TypeIndicatorContext
IPV477[.]91[.]100[.]175Hardcoded C2 address used by five credential- and clipboard-stealing extensions.
SHA25608b7b064fa9a41b06774315d944ffddff705ab727222a0c3bcac64a77553bf2fPackage hash listed for a confirmed malicious Firefox extension.
SHA2560e163cde2337fbc11232b548e301dea746b764b898e0decbfcc7940248d4f092Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2561381fc82afd785cb0dfc2cf511ed49d4487cb9cd4edee9f741b38710624a1bd0Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA2561429f5134b5acf5077a18cf805bc905393524debad75f70a942ec30608f49088Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25614a2da218e41d3854e731d02f8a444a1b9712ba2788d57b5a76c18737bd559aePackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256172b7618498d1c9da6ff6aecc8f680d2b3956b7c86d80fbc060e0adae8f38ebfPackage hash listed for a confirmed malicious Firefox extension.
SHA2561753fa38657c6c0d23ff7ca12a768a1b23ac3d8f3896c746ae2bdc7538c03009Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2561857acb44d3e577645f7ca64e76a14609d960c6a6efa56ea00c28ac43df4463fPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2561b3634aec03d85d9e7463e363b6664e9105f17badfa5f1cf737b1623267ae631Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2561cbe34e76e4ebb1e8b185f67e8f5bc507427af7692512b9e6a93ec6051685d95Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA256252119fc48ad93b0c930d7a62fb49420cf8986716539e4e9d4d5c1bad700d435Package hash listed for a confirmed malicious Firefox extension.
SHA25626427220b9965e22deca0e617657c2c65b78f750183355d1265c147818367bd7Package hash listed for a confirmed malicious Firefox extension.
SHA2562a0856637d0e3850b153713ef34d1963b6d6b06acaa1e4fbdc6fa305483987caHistorical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA2562b0d50aa0edf4f65e21b015fee169d68dc870a89d242836ccb3c7cef84db04c4Package hash listed for a confirmed malicious Firefox extension.
SHA2562fb5b89c0889a8bde90845de2db13161f6d8845fa5dbc56bfa474f800c664d9ePackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25631dc33e75aa2a9e64eac98467c5a516201e208d68ffe10d07800350ce1a44197Package hash listed for a confirmed malicious Firefox extension.
SHA25636b8cbed79b91b92e84eb01d61c57c8972cacc68a3d6a3629e2a2b25a59ee11dPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25639827e214c31dbbf0ce20a40ee019cca2d96d621bf90dac4edc8b85a86311d09Package hash listed for a confirmed malicious Firefox extension.
SHA2563c0f0413ca6326bd0107d532aec4daad7feec663d072f7c992682fb702b64ccePackage hash listed for a confirmed malicious Firefox extension.
SHA2563e4cd172c21c0c0d72c762fe84f07a9eb8f7c82f15add36bdf934ee42accf776Package hash listed for a confirmed malicious Firefox extension.
SHA2563f52fcb79e2b8e255030b1270f22618417e622e65406cf6e3e715e2f0a80b9e3Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2563f73e8af9eb2d664be44e07955253a59c5dab684c645ab648f36c2cbccddcdb3Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25640f6611eacbcf10f6260f91caeb4a2223313f466340f3ea9d47d6e34ee8b889aPackage hash listed for a confirmed malicious Firefox extension.
SHA25646305296e0675147c7b4ceacc7d5e45dd44d5d2242c0c3e02b444931b3e1564bPackage hash listed for a confirmed malicious Firefox extension.
SHA25646c40d3cefb10a9fd1dfeb03ff1dc550674d391bdf05c0294257809d51c254a8Package hash listed for a confirmed malicious Firefox extension.
SHA2564d0912d575087dab5f468214a2fd259bc386472a8b2b93b6e2441cde4bd941cbPackage hash listed for a confirmed malicious Firefox extension.
SHA2565328d5e600d1de7e4ffe8bd38dd1fdf22f1226b21c4d77db10aca7c9ce31c2a8Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA256547a878083e4e3c39c240f27e9caaa190ef04661f46468234987980d907d9834Package hash listed for a confirmed malicious Firefox extension.
SHA25654d57acdd0557e22f9dd1350ac1bf1f536dd5859394b39cf9ba586b3d2339f05Package hash listed for a confirmed malicious Firefox extension.
SHA25656a6dbde57aab6ab2f4f1d5af1d6fbc3e775a600026382e56df7ef5363c50d4dPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25657d78328f2cd02e91e511fbee80fc2dc43368adf0c84fac4cc0bbbce3fad5d8aPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2565a7227dbf8e5c5c73f11c7df221c080252b337cb96b21f462d5ef17525f00f16Package hash listed for a confirmed malicious Firefox extension.
SHA2565bebc15d404c4f7314f4e4cd7e24aff1178de124374128bc845a034e3f6c9853Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2565c8121bd3394c4ea6d273a6936aeaa7d30aa748a978b440d7144819522813153Package hash listed for a confirmed malicious Firefox extension.
SHA2565dcbce26e54dd44d0b932e23f1a741298d4e35487d1868b469518f903e577a7aHistorical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA2565dd33e0737e82b2e324dc4c04ce862da185153d54705697cfd0181e848bf35d4Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25661659464d6ac002757b51c276f22cd3fff25089c1dc257c0b81309bf49aba7c0Package hash listed for a confirmed malicious Firefox extension.
SHA25661a19cab5c7bbcf5ded1c8b6a05d586ecbe03afc055c132049226f86f5127b3dPackage hash listed for a confirmed malicious Firefox extension.
SHA2566408b6a2c4000e74cde94d3ce31ada5e024d80782199e8010d6ef482686e687bPackage hash listed for a confirmed malicious Firefox extension.
SHA25666150abf5072f0d02118648d072afecdc8bac1d224dbc569836a65398d48e98dPackage hash listed for a confirmed malicious Firefox extension.
SHA25668b25a9761e04f3c68af6d94e2ad3ca259ebbaf06e90798d6c2613ddc3e434c4Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA2566a3c00936b7f62652eb4970b2bd3bb895fdd9ec1ebae1dab19f0c50cfbdc6b4cPackage hash listed for a confirmed malicious Firefox extension.
SHA2566db5ea393b1618259fee5a2ca7467be47ea025255d2ab45a78b76e23e4e0b59ePackage hash listed for a confirmed malicious Firefox extension.
SHA256708291399f6d98529e02a1d0100084abfe1e09d3fb7d8fefad744f1e7f439420Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256716cc37e2019a92ab1970d74e3ee962cafb4eef97fbd55353f15a34c8e0c2a30Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25671f74a903b12fdaa1cb7683599b7956602768f23934578171f6453fdee7b3eacPackage hash listed for a confirmed malicious Firefox extension.
SHA256790c869021cf7584271c73cb4eac8a094595e7225f69acc1a4b145903b2bc1c2Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256793a2d26dc9781bbf3e61db85009626f7de9edc19bddc349f29b4cf74d1b184ePackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2567d950ad43d7e83f8f84a2033f88349d384972a9b69cde3cc2ca1ee28e1be94edPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2568590d1a22fdf42a363fe41fe6dc2cb03e616cc6d413f63d2ade9fd3ab54f1c83Package hash listed for a confirmed malicious Firefox extension.
SHA25688d5b16c767e2527c14d2ae25dca6f4fe19f69517d0e00a2f26be055c575e3fePackage hash listed for a confirmed malicious Firefox extension.
SHA256894109c97ccb215f523e41bc968ffa7716959c62c7c3f625cf4c03d50e899072Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256894398430972f91db2f1916f9fbe28b7319cb0e7d0e91a51e764fda5e7d1e8c9Package hash listed for a confirmed malicious Firefox extension.
SHA2568cec7990d4bc5e45034796fc63c63ba16781ac4303925ed1e80036668a9fe48ePackage hash listed for a confirmed malicious Firefox extension.
SHA256918332da18e0f26378ee84408be13930da2d66cd80153cf18a5aa3d6d0cb2271Package hash listed for a confirmed malicious Firefox extension.
SHA25696be1669cbc95c35a5448311fb808cf915ea89cdee983ae905f903f9fcb5bb6dPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA25696d03bb2b8a59db38200278dc17fbafc14c55795a126068f3e7a3fc7a749730fPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA2569c6f173418245a953d5fc3e9ec69f09b7aee8563127042a995ad172de9cdb88dPackage hash listed for a confirmed malicious Firefox extension.
SHA256a2eba930f94306f2f4f27b74351c1ce0a75210bac51d9efa09c71d69d3cb9990Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256a3a31d7338b047de63b5c92a8d697292a26b0fccb4797918462139b8767d97f8Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256a3d9369e666aeb7230956bd6dd97b7337b829c5ae5139171e90593de17dc9b08Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256aa9d8f30bd6e0633af5bb0fa16ed2e87fcd22e87725c48a5c96884465e262a28Package hash listed for a confirmed malicious Firefox extension.
SHA256acf6f82916e78b2e5326fd16d6c97206532305cf5d68ea21e1a30537bffd26c0Package hash listed for a confirmed malicious Firefox extension.
SHA256aeb6240b2f40a177999f68ae6fc88e511669d501aa298a433b05bafa89210685Package hash listed for a confirmed malicious Firefox extension.
SHA256af69e15e02d4c2850a6ed26e9d7d1152e16e2d7d01695bbf3b3840adf0b6bee5Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256b44c7cd048bbe7f165fd28a755765c978373ee6761b6ae306ba57e9e1895536bPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256b65143df86edd60625fcbc0fcb396ef02baae6e731c1993e70873563e5a1524cHistorical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA256b8b5ad5c18626e11bf4960a8245539334367be6655bd4c21140bb27c82efb679Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256bdcb3789c063a06369ff73906d7776846a163d6c60ff8dbcc549bc2dfe5ea382Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256bee995e253092c8c8edfa4104799adbe40967596dfdb28a5668390aea40d0883Package hash listed for a confirmed malicious Firefox extension.
SHA256c7435c1659b6e0dc83487d03b3389ec22bb7e435c9b4c85a81f6c6504466060bPackage hash listed for a confirmed malicious Firefox extension.
SHA256d5c5331b82771fe91213c246d076ad6d08157b5390fabb4a1d7209b1a5db15ddHistorical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA256d671be66381149dc7efb9c77f081fc1e3410cbf2447fe7652b77b08f895503d8Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256e0373ebe9eec5ec6734bbbd012fc9874c78b35f7cd444e9df1461f8d03d3b0d0Historical sports-shell package under a Firefox ID later confirmed malicious; this earlier build was not confirmed to steal secrets.
SHA256e335066fb09d0d9d0e5fd55b946d430071fb6f157bdb9b38e7f50714178a51ebPackage hash listed for a confirmed malicious Firefox extension.
SHA256e4c3a669362e8b456b1d6c8e6df7da2a9605a42d710d0cc951342b7ac0cb9d72Package hash listed for a confirmed malicious Firefox extension.
SHA256e4f351a6d6a8249691eec07223c74ca9c8708522919e1626baef705acb1ad87dPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256e7ef1558ecba876e2786e5f281d5551e2ab161c52f3443e5c81f4ffd0ba17d5bPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256eb4718f52161d2262e9aa83b4b561fa475486f5183600376d002be3333823787Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256ed63c3a14b51915863bbc443f169dccb73baebdc4e553cdfe18ef1a68b72ffb2Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256edcdbcdbea729fb11cbb0a353c3a9025e5a29de48fcd86e3948df738bf82b2aaPackage hash listed for a confirmed malicious Firefox extension.
SHA256eeb1969d0c8b250976ec220f40236ddd7eb6863556379d17e1dd4078b5531751Package hash listed for a confirmed malicious Firefox extension.
SHA256eec0638729b096e0d0f93173be9b105b15371b76c167dfa89e5a882ee290d9cbPackage hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256f0d262d1b1e446ee1a6db37b0301b9e2ab160269b193920212d55d7dfb231fe1Package hash listed for a confirmed malicious Firefox extension.
SHA256f70febe6549d1439cf1f140cae18f13e7150ffe4ca31e3e00656b878a0153366Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256fc74265e10942ee96726c7cce9b642cc7492835cb4eb43d4451bd2aab13e1ec8Package hash of a deceptive sports-score shell associated with malicious intent; theft was not confirmed in this build.
SHA256fd67f4a3c8993b1ce6aecf0cc8902e6a8535a6ef56c0bad42d7e936d0a17e060Package hash listed for a confirmed malicious Firefox extension.
URLhxxp[:]//77[.]91[.]100[.]175/html/app[.]phpC2 URL receiving captured credentials.
URLhxxp[:]//77[.]91[.]100[.]175/html/continue[.]phpC2 URL receiving chunked clipboard contents.
URLhxxp[:]//alt[.]e-wl[.]com:9000/hook/altSerialized-keyring exfiltration endpoint.
URLhxxp[:]//consol[.]e-wl[.]com:9000/hook/cosomidSerialized-keyring exfiltration endpoint.
URLhxxp[:]//firebase[.]e-wl[.]com:9000/hook/seeSerialized-keyring exfiltration endpoint.
URLhxxp[:]//id[.]gemachriverdale[.]org:9000/hook/pastreSerialized-keyring exfiltration endpoint.
URLhxxp[:]//id[.]gemachriverdale[.]org:9000/hook/ptvveHTTP endpoint used to collect serialized wallet keyrings before local encryption.
URLhxxp[:]//id[.]gemachriverdale[.]org:9000/hook/rraSerialized-keyring exfiltration endpoint.
URLhxxp[:]//mapid[.]e-wl[.]com:9000/hook/mapidSerialized-keyring exfiltration endpoint.
URLhxxp[:]//ommid[.]e-wl[.]com:9000/hook/ommidSerialized-keyring exfiltration endpoint.
URLhxxp[:]//pch[.]e-wl[.]com:9000/hook/pchSerialized-keyring exfiltration endpoint.
URLhxxp[:]//rest[.]e-wl[.]com:9000/hook/restSerialized-keyring exfiltration endpoint.
URLhxxp[:]//temple[.]e-wl[.]com:9000/hook/templeSerialized-keyring exfiltration endpoint.
URLhxxp[:]//typec[.]e-wl[.]com:9000/hook/typoSerialized-keyring exfiltration endpoint.
URLhxxp[:]//vala[.]e-wl[.]com:9000/hook/valueSerialized-keyring exfiltration endpoint.
URLhxxps[:]//acrfruxtmulgvyvtbwgq[.]supabase[.]coCampaign-embedded Supabase project URL used as a remote-control artifact.
URLhxxps[:]//dry-bush-5408[.]animalrescueeducationcenter-org[.]workers[.]dev/Threat actor-controlled Cloudflare Worker endpoint receiving stolen recovery phrases.
URLhxxps[:]//dry-bush-5408[.]animalrescueeducationcenter-org[.]workers[.]dev/?a=login&s=EQOx7EIPZSNi&k=login&w=<mnemonic>Article's observed recovery-phrase exfiltration request pattern.
URLhxxps[:]//efiukydskwkeatexavdp[.]supabase[.]coCampaign-embedded Supabase project URL used as a remote-control artifact.
URLhxxps[:]//kyfyvuwifdukctqyggto[.]supabase[.]coCampaign-embedded Supabase project URL used as a remote-control artifact.
URLhxxps[:]//mzghdnikguesdamuxjbm[.]supabase[.]coCampaign-embedded Supabase project URL used as a remote-control artifact.
URLhxxps[:]//nxsixihozitybwrbahiu[.]supabase[.]coCampaign-embedded Supabase project URL used as a remote-control artifact.
URLhxxps[:]//portal-web3-extension-welcome[.]pages[.]dev/homeThreat actor-controlled wallet-phishing page loaded by the remote-controlled extension.
URLhxxps[:]//quiet-thunder-ade3[.]bankoganger[.]workers[.]dev/Cloudflare Worker endpoint identified as campaign exfiltration infrastructure.
URLhxxps[:]//vgksucdjccsojzuhckzk[.]supabase[.]coSupabase project URL embedded in the malicious Rabbit For Desktop remote loader.
URLhxxps[:]//vnigkfdwwyphfafficet[.]supabase[.]coResidual Supabase configuration embedded in the fake OKX extension.
URLhxxps[:]//winter-smoke-a612[.]icy-star-f45c[.]workers[.]dev/Cloudflare Worker endpoint receiving stolen wallet secrets.
URLhxxps[:]//winter-smoke-a612[.]icy-star-f45c[.]workers[.]dev/?a=login&s=EQOx7EIPZSNi&k=login&w=<mnemonic>Article's observed recovery-phrase exfiltration request pattern.
URLhxxps[:]//winter-waterfall-0606[.]rihaniomar21[.]workers[.]dev/Cloudflare Worker endpoint receiving secrets from a counterfeit wallet extension.
URLhxxps[:]//winter-waterfall-0606[.]rihaniomar21[.]workers[.]dev/?w1=<mnemonic>Article's observed wallet-secret exfiltration request pattern.
URLhxxps[:]//winter-waterfall-0606[.]rihaniomar21[.]workers[.]dev/?w1=<wallet_secret>Counterfeit OKX wallet's described secret-exfiltration request pattern.
URLhxxps[:]//yvqmtnmeivrcyomyeouz[.]supabase[.]coCampaign-embedded Supabase project URL used as a remote-control artifact.

MITRE ATT&CK

T1005 · Data from Local SystemModified Rabby-derived extensions obtained serialized local keyring data during the wallet persistence workflow.T1020 · Automated ExfiltrationEmbedded extension logic automatically transmitted captured recovery phrases, keyrings, credentials, or clipboard contents.T1030 · Data Transfer Size LimitsClipboard-stealing extensions split captured contents into numbered chunks for transmission.T1036.005 · Match Legitimate Resource Name or LocationExtensions used wallet-like names, branding, and visually similar characters to resemble legitimate wallet products.T1041 · Exfiltration Over C2 ChannelFive credential- and clipboard-stealing extensions sent collected data to their hardcoded C2 server.T1056.002 · GUI Input CaptureCounterfeit wallet-import interfaces prompted victims to type recovery phrases or private keys.T1059.007 · JavaScriptJavaScript in extension packages queried Supabase for remote content and implemented wallet-secret or clipboard collection.T1071.001 · Web ProtocolsExtensions used HTTP or HTTPS requests to query remote controllers and transmit stolen secrets to collection endpoints.T1102.001 · Dead Drop ResolverRemote-loader extensions queried a Supabase table for the latest content value to obtain a URL for remotely selected phishing content.T1115 · Clipboard DataFive extensions monitored and collected clipboard contents.T1176.001 · Browser ExtensionsThe operation published malicious and deceptive Firefox browser extensions, including extensions later repurposed under existing IDs.T1204 · User ExecutionWallet-phishing workflows depended on victims installing extensions and entering recovery phrases or private keys.

Vendors

Products

Cloudflare Pagesit in a separate window after installation or update. The destination, hosted through the legitimate Cloudflare Pages service, presents a polished Web3 interface with Create wallet and Import wallet options.Cloudflare Workers15 capture recovery phrases, private keys, or other wallet secrets and exfiltrate them through Cloudflare Workers. 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption, while fiveFirefox Add-onsIts Firefox Add-ons listing used OKX-style branding and screenshots, described the extension as a universal Web3 wallet, and claimed that it collected no data. The name substitutes a zero for the letter “O” in OKX,Mozilla FirefoxThe Socket Threat Research team is tracking 77 Firefox extension identities linked through code reuse, cloned extensions, deceptive marketplace descriptions, author-selected add-on ID patterns and domain-like suffixes,OKXThe malicious extensions impersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases,Rabby WalletThe malicious extensions impersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases,Supabaseimpersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases, private keys, or otherTronLinkThe malicious extensions impersonate OKX, Rabby Wallet, TronLink, and other Web3 products. Seven use threat actor-controlled Supabase projects as remote switches for phishing content. 15 capture recovery phrases,

Tools

Related Articles