Researchers uncovered a long-running Firefox extension campaign, dubbed Offside Wallet Theft Factory, that used dozens of linked add-ons to steal cryptocurrency wallet seed phrases and browser credentials. The operation had been active since at least March 2026 and involved 77 related extensions, with 40 confirmed as malicious. The add-ons impersonated legitimate Web3 and wallet tools, targeting users seeking browser-based cryptocurrency functionality.
One extension highlighted by researchers, 0KX WEB3, presented itself as a crypto wallet but lacked real wallet features. Instead, it queried a Supabase-hosted database that allowed the operators to remotely change the extension from a benign-looking decoy into a phishing interface designed to capture wallet import secrets and passwords. The findings show that even extensions requesting limited permissions can still be weaponized, and that clusters of seemingly harmless add-ons sharing code or infrastructure may later be updated into credential- and wallet-stealing malware.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Socket researchers said the linked malicious Firefox add-on campaign they dubbed the "Offside Wallet Theft Factory" has been operating since at least March 2026. The campaign used Firefox extensions tied together by shared code and infrastructure.
Socket reported that 13 extensions used modified Rabby wallet code to exfiltrate serialized keyring data before local encryption, while 15 displayed counterfeit wallet-import forms that sent recovery phrases and private keys to Cloudflare Workers. A separate cluster of five extensions stole credentials and clipboard contents and transmitted the data over plain HTTP to a hardcoded command-and-control server.
Offside Wallet Theft Factory operators published seemingly benign sports-score services and utilities in the official Firefox add-on catalog, then later updated some under the same Firefox IDs into credential and cryptocurrency-wallet stealers. Researchers identified nine add-ons whose earlier versions provided real football, basketball, or American-football scores before becoming malicious.
Researchers described a malicious Firefox extension named "0KX WEB3" that impersonated a crypto wallet but contained no real wallet functionality. Instead, it queried a Supabase-hosted database that allowed attackers to remotely switch it from a harmless decoy into a wallet-import phishing interface that captured seed phrases.
Researchers identified 77 related Firefox extensions associated with the campaign, with 40 confirmed to steal cryptocurrency wallet seed phrases or password details. The remaining 37 posed as benign tools such as VPNs, password generators, or note-taking apps while sharing the same infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityonline.info
Open sourcebitdefender.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.