Researchers uncovered a campaign dubbed Offside Wallet Theft Factory that used at least 40 malicious Firefox extensions impersonating Web3 products including OKX, Rabby Wallet, and TronLink to steal cryptocurrency wallet data. The operation is tied to a broader cluster of 77 browser add-ons sharing source code and infrastructure, and is believed to have been active since March 2026. Investigators said some of the add-ons were initially published on the official Firefox marketplace as benign sports-score or utility extensions before being repurposed under the same Firefox IDs into wallet-stealing malware.
The extensions used several theft methods, including fake wallet pages and phishing redirects, embedded logic to capture seed phrases, serialized keyrings, credentials, and clipboard contents, and exfiltration through Cloudflare Workers and attacker-controlled Supabase projects that also acted as remote switches. Reporting also identified recurring code markers and infrastructure overlap across the packages, including shared request tokens, hard-coded command-and-control elements, custom hook endpoints, a dedicated IP address, and a phishing page on pages.dev delivered by a fake 0KX WEB3 extension. The activity has not been attributed to a known threat actor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Socket researchers assessed that the Firefox extension campaign later named Offside Wallet Theft Factory had been active since March 2026. The operation used browser add-ons tied to cryptocurrency wallet theft and deceptive extension publishing.
Published technical details showed the campaign used Supabase projects as remote switches, Cloudflare Workers to exfiltrate wallet recovery phrases, dedicated endpoints for serialized keyring theft, and 77.91.100.175 for credential and clipboard collection. The indicator set also identified a pages.dev phishing page delivered by the fake 0KX WEB3 extension and listed package hashes, IDs, and recurring code markers across the malicious extensions.
Socket assessed another 37 Firefox extensions as part of the same coordinated operation based on shared publishing artifacts, code overlap, and deceptive functionality. These sports-themed add-ons did not contain confirmed wallet-stealing payloads in the analyzed versions but were considered part of the broader campaign.
Researchers confirmed 40 Mozilla Firefox extensions were malicious and impersonated Web3 products such as OKX, Rabby Wallet, and TronLink to steal wallet secrets, credentials, and other sensitive data. They linked these to a broader cluster of 77 browser add-ons with shared code and overlapping infrastructure and named the campaign Offside Wallet Theft Factory.
Historical versions of some Firefox add-ons first appeared as sports score or utility extensions on the official marketplace and were later converted under the same Firefox IDs into crypto-wallet-stealing malware. Socket reported this repurposing affected nine confirmed malicious extension identities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 142 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.