Software supply-chain security firm Socket identified 40 Firefox add-on identities exhibiting confirmed malicious behavior, including capabilities to drain cryptocurrency wallets. Notably, nine of these extensions had previously operated as sports-score tools under the same identifiers before being repurposed.
Users whose recovery phrase, private key, or wallet keyring was accessed by any of these malicious versions must consider their wallet compromised. Simply uninstalling the extension does not revoke an exposed secret.
Socket’s August 19 report linked 77 identities to what the firm provisionally designates as the “Offside Wallet Theft Factory,” with 40 confirmed to contain malicious behavior. The remaining 37 were identified as deceptive or suspicious sports-score shells whose analyzed versions did not yet contain confirmed theft payloads.
The campaign operated from at least March through August. Mozilla signing records for the 59 versions analyzed by Socket spanned from March 9 through August 3, with activity concentrated in April and late July.
Socket’s version histories reveal that the nine affected identifiers were:
| Firefox IDE | Earlier sports version | Later malicious version |
|---|---|---|
| bright-save-feed@tabtools.org | Quick Quick 7.4.0 | Rabbit For Desktop 8.20.10 |
| swift-clip-link@fasttools.co | Dial Open Pro 7.23.25 | Web3 & EVM 9.50.10 |
| deep-tip-sharp@browsify.co | Quick Shield 5.7.1 | Rby-WALLEТ 6.7.10 |
| bolt-save-vault@devplugs.co | Lite Swatch 6.5.21 | abby-WALLEТ 7.10.10 |
| core-note-nova@webtools.net | Key Pulse 8.1.21 | RABB-Walleť 8.22.30 |
| gear-save-tip@extrakits.example | Timer Pulse 5.5.5 | Rabbit WALLЕТ 11.10.10 |
| flex-lab-save@foxplugin.co | Track Quick 6.10.24 | RabbWALLЕТ 7.10.30/8.10.30 |
| pure-net-snap@fasttools.co | Store Plus 8.3.18 | RabbWALLЕТ 9.11.30 |
| fast-zip-true@smartext.co | Pomodoro Plus 9.13.24 | RABB-WALLEТ 10.20.10 |
Socket noted that several campaign add-ons remained active when reported to Mozilla. The remote-controlled phishing extension 0KX WEB3 was live with seven users during analysis, and Mozilla removed it prior to publication.
Recommended Actions for Affected Crypto Users
The 40 malicious identities employed distinct attack vectors. Seven functioned as remote-controlled phishing loaders, 15 captured recovery phrases, private keys, or other cryptocurrency wallet secrets, 13 were modified clones of Rabby wallet software that transmitted serialized keyrings before local encryption, and five collected credentials and clipboard data.
A recovery phrase or private key can restore a wallet on another device, and a serialized keyring similarly exposes the wallet’s account state before encryption protections take effect.
Users who entered any of these secrets, or utilized an affected build that transmitted its keyring, should transfer remaining assets to a freshly created cryptocurrency wallet generated from a new recovery phrase.
Users exposed only to the credential-and-clipboard group should change affected passwords, terminate active sessions where possible, and verify copied destination addresses. Wallet key rotation is necessary when wallet-secret or keyring exposure occurred.
Mozilla states it employs automated risk indicators and human review to identify malicious wallet extensions, advising users to install only extensions linked from official wallet provider websites.
Socket documented the theft capabilities and exfiltration infrastructure but did not identify confirmed victims, attributable transactions, or a total campaign loss amount.


