Security researchers have uncovered a large network of malicious and deceptive Firefox extensions connected to a campaign targeting cryptocurrency users. The operation, active since at least March 2026, includes add-ons capable of stealing wallet recovery phrases and credentials.
Researchers at Socket have named the operation the “Offside Wallet Theft Factory.” Their investigation linked 77 Firefox extension identities through shared code, similar publishing patterns, reused infrastructure, misleading marketplace descriptions, cryptocurrency wallet impersonation, and evidence that some extensions changed purpose through later updates.
Analysis confirmed that 40 of the extensions contained malicious functionality designed to obtain wallet secrets or other credentials. Another 37 presented themselves as sports-related extensions offering live results for football, basketball, NBA, and hockey.
The sports extensions are particularly notable because they can initially appear legitimate. According to Socket, they contain working score functionality while their marketplace descriptions advertise various unrelated capabilities, including VPN services, password generation, currency conversion, dark mode, screenshots, and note-taking. Researchers warned that such extensions could establish credibility before being repurposed through subsequent updates.
One example demonstrates how attackers are also exploiting recognizable cryptocurrency brands. An extension called “0KX WEB3” was designed to resemble the name of crypto exchange OKX, replacing the first letter with the number zero.
Rather than providing an actual cryptocurrency wallet, the extension contains a functioning notepad alongside infrastructure that allows remotely supplied content to be loaded into its interface. Researchers discovered a hardcoded Supabase project URL and anonymous API key, as well as functionality for retrieving a remotely configured URL.
When opened, the extension queries a table within the attackers’ Supabase project and retrieves its latest content value. This mechanism allows the operators to determine what webpage victims see without having to publish another version of the extension.
Users can subsequently be presented with a convincing wallet-import page. Entering a recovery phrase into that page sends the sensitive information to the attackers, potentially providing them with what they need to access the associated cryptocurrency wallet.
Socket therefore classified “0KX WEB3” as a remotely controlled phishing delivery mechanism rather than a traditional information-stealing extension.
Following disclosure of the campaign, Mozilla’s Add-ons Operations team removed and blocklisted the identified malicious extensions from the official Firefox Add-ons Store. Mozilla had previously introduced additional protections intended to detect fake cryptocurrency wallet extensions submitted to its marketplace.
The findings highlight a particularly serious risk for cryptocurrency owners because wallet recovery phrases can provide access to digital assets independently of normal account passwords. Removing a malicious extension after a recovery phrase has already been exposed does not invalidate the compromised phrase.
The campaign also demonstrates why an extension’s current behavior alone may not reveal its future risk. An add-on can initially provide the advertised functionality and later receive an update that introduces different or malicious capabilities.
Site Disclaimer
2-remove-virus.com is not sponsored, owned, affiliated, or linked to malware developers or distributors that are referenced in this article. The article does not promote or endorse any type of malware. We aim at providing useful information that will help computer users to detect and eliminate the unwanted malicious programs from their computers. This can be done manually by following the instructions presented in the article or automatically by implementing the suggested anti-malware tools.
The article is only meant to be used for educational purposes. If you follow the instructions given in the article, you agree to be contracted by the disclaimer. We do not guarantee that the artcile will present you with a solution that removes the malign threats completely. Malware changes constantly, which is why, in some cases, it may be difficult to clean the computer fully by using only the manual removal instructions.