Build1 distinct publisher3 min readUpdated
Socket says 40 of the 77 extensions it tracked are confirmed credential and wallet stealers, and nine of them were repurposed from sports-score shells under the same add-on IDs.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Socket's Threat Research team says it is tracking 77 linked Firefox extension identities, of which extension-level analysis confirms 40 as stealing wallet secrets or credentials [1][2]. Nine of those 40 shipped earlier versions as sports-score shells and were later repurposed into wallet-stealing builds under the same stable Firefox add-on IDs [4], which is the part that should change how you write endpoint policy.
The remaining 37 identities are, per Socket, a coordinated multi-sport score-shell operation: the analysed builds contained no confirmed stealing payload, but the deceptive functionality, shared publishing artifacts and version histories point to intent [3]. Those shells share a hardcoded credential for the legitimate API-Sports service while advertising themselves as password generators, dark mode toggles, VPNs, currency converters, screenshot tools and note takers [18]. A password generator that is actually a football scoreboard is not a subtle disguise, and it passed listing anyway.
The confirmed 40 impersonate OKX, Rabby Wallet, TronLink and other Web3 products [7]. Socket breaks the mechanics into four groups: seven use threat-actor-controlled Supabase projects as remote switches for phishing content [8]; 15 capture recovery phrases, private keys or other wallet secrets and exfiltrate them through Cloudflare Workers [9]; 13 are modified Rabby Wallet builds that exfiltrate serialized keyrings before local encryption [10]; and five steal credentials and clipboard data through hardcoded command and control [11]. Those four groups sum to exactly the 40 confirmed identities [12]. The 13 Rabby builds are the sharpest case: the theft happens upstream of the wallet's own encryption, so the user's passphrase hygiene is irrelevant.
On timing, Socket says the campaign has run since at least March 2026 and continued into August [13], with Mozilla signing records for the original 59 analysed versions spanning March 9 to August 3 and activity peaking in April and late July [14]. That is a 147-day signing window [15]. Investigation through mid-August turned up 18 more campaign-linked identities, expanding the tracked set to 77, with several still live when Socket reported them to Mozilla's security team [16][21]. Socket is calling the cluster "Offside Wallet Theft Factory" and says attribution remains under investigation, with the available evidence not establishing that a single actor controls every extension [19][20].
The operational lesson is narrow and worth taking literally. Review approves a build; the identity persists across builds. Socket's own linkage criteria include version histories in which stable Firefox IDs move from shell or utility builds into wallet malware [24], so an allowlist keyed on add-on ID alone inherits that gap. If you allowlist, pin versions where your management tooling supports it, block install from any source other than your own approved set, and alert on version changes to approved extensions rather than only on new installs. The remaining 31 confirmed identities had no sports API at all and were malicious from the builds analysed [5], so the repurposing route is one path in, not the only one [6].
Socket also notes the asymmetry that makes this worth budget: a wallet extension does not need to survive long, because exposure of a recovery phrase or private key is immediate and irreversible [22]. Detection latency measured in days is a loss.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Shared code, infrastructure, campaign tokens, repeated add-on ID patterns, domain-like suffixes, clustered signing activity, misleading metadata and direct version histories showing stable Firefox IDs transition from shell or utility builds into wallet malware indicate a common publishing pipeline or closely related threat actors.
Socket's Threat Research team is tracking 77 Firefox extension identities linked through code reuse, cloned extensions, deceptive marketplace descriptions, author-selected add-on ID patterns and domain-like suffixes, cryptocurrency-wallet impersonation, and version histories showing extension repurposing.
Extension-level analysis confirms 40 of the tracked extensions as malicious, stealing wallet secrets or credentials.
Another 37 extensions form a coordinated multi-sport score-shell operation; their analysed builds contain no confirmed credential- or wallet-stealing payloads, but their deceptive functionality, shared publishing artifacts and version histories indicate malicious intent.
Historical versions of nine confirmed malicious identities used sports-score shells spanning football, basketball, NBA and American football before later versions under the same Firefox IDs were repurposed into wallet-stealing extensions.
The other 31 confirmed malicious identities lack the sports API integration but contain confirmed malicious wallet- or credential-stealing functionality.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party forensics, no external verification
The single source provides unusually specific, internally consistent technical evidence: per-mechanism counts that reconcile to the 40 confirmed malicious extensions, subgroup counts that reconcile to the same total, Mozilla signing dates for 59 versions, a named shared API-Sports credential, and a code-level walkthrough of one extension's Supabase-driven phishing loader. It is capped below high confidence because everything comes from the vendor that found it, no Mozilla or third-party confirmation appears, and the 37-extension half of the corpus rests on inferred intent rather than observed payloads.
Wide store presence, negligible disclosed installs
Real-world uptake of the malicious extensions is measurable only weakly: 77 identities existed as live or formerly live Firefox listings with 59 signed versions across roughly five months, and several were still live at reporting - but the only install figure disclosed anywhere is seven users on the 0KX WEB3 clone. No aggregate install totals, victim counts, or stolen-funds figures are provided, so distribution breadth is documented while actual victim reach is not.
Framing slightly ahead of certified findings
Mildly overstated. The headline framing of one pipeline behind 77 add-ons runs ahead of the vendor's own hedge that attribution is open and single-actor control is not established, and 37 of the 77 are judged malicious on intent signals rather than observed payloads. Harm is asserted as immediate and irreversible with no victim or loss figures and only a seven-user install datapoint to anchor scale. The gap stays small because the source is explicit about these limits rather than concealing them, and the 40 confirmed cases are documented mechanism by mechanism.
Vendor research promoting its own coverage
The sole source is a commercial supply-chain security vendor publishing research on its own product surface. Socket names the campaign itself, and closes by positioning its Firefox ecosystem coverage as complementing Mozilla's protections - a direct commercial framing. There is no adversarial review, no affected-platform statement, and no independent replication in the cluster, so the incentive to maximise the headline corpus size (77 tracked, of which 40 confirmed) is unchecked.
Technically strong, single-publisher and unquantified impact
Confidence is moderate. The technical narrative is granular, dated, and internally reconcilable, and the vendor flags its own limits on attribution and payload confirmation. But the cluster has exactly one publisher with a commercial stake, no platform confirmation of takedowns, and no measured victim or install scale beyond one seven-user listing, so the scope and impact of the campaign cannot be corroborated from the supplied material.
build
Socket turns on continuous scanning for all 97,100 Firefox add-ons1 distinct publisher
build
The npm audit that works because it never installs the package1 distinct publisher
build
AWS gives software supply chain its own Security Hub category, with two vendors in it1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026