Build1 publisher3 min readPublished
77 linked Firefox add-ons, one pipeline: store review is a checkpoint, not a control
Socket says 40 of the 77 extensions it tracked are confirmed credential and wallet stealers, and nine of them were repurposed from sports-score shells under the same add-on IDs.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Socket's Threat Research team is tracking 77 Firefox extension identities linked through code reuse, cloned extensions, deceptive marketplace descriptions, author-selected add-on ID patterns and domain-like suffixes, cryptocurrency-wallet impersonation, and version histories showing extension repurposing.
- Extension-level analysis confirms 40 of the tracked extensions as malicious, stealing wallet secrets or credentials.
- Another 37 extensions form a coordinated multi-sport score-shell operation; their analysed builds contain no confirmed credential- or wallet-stealing payloads, but their deceptive functionality, shared publishing artifacts and version histories indicate malicious intent.
- Historical versions of nine confirmed malicious identities used sports-score shells spanning football, basketball, NBA and American football before later versions under the same Firefox IDs were repurposed into wallet-stealing extensions.
- The other 31 confirmed malicious identities lack the sports API integration but contain confirmed malicious wallet- or credential-stealing functionality.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Socket's Threat Research team says it is tracking 77 linked Firefox extension identities, of which extension-level analysis confirms 40 as stealing wallet secrets or credentials [1][2]. Nine of those 40 shipped earlier versions as sports-score shells and were later repurposed into wallet-stealing builds under the same stable Firefox add-on IDs [4], which is the part that should change how you write endpoint policy.
The remaining 37 identities are, per Socket, a coordinated multi-sport score-shell operation: the analysed builds contained no confirmed stealing payload, but the deceptive functionality, shared publishing artifacts and version histories point to intent [3]. Those shells share a hardcoded credential for the legitimate API-Sports service while advertising themselves as password generators, dark mode toggles, VPNs, currency converters, screenshot tools and note takers [18]. A password generator that is actually a football scoreboard is not a subtle disguise, and it passed listing anyway.
The confirmed 40 impersonate OKX, Rabby Wallet, TronLink and other Web3 products [7]. Socket breaks the mechanics into four groups: seven use threat-actor-controlled Supabase projects as remote switches for phishing content [8]; 15 capture recovery phrases, private keys or other wallet secrets and exfiltrate them through Cloudflare Workers [9]; 13 are modified Rabby Wallet builds that exfiltrate serialized keyrings before local encryption [10]; and five steal credentials and clipboard data through hardcoded command and control [11]. Those four groups sum to exactly the 40 confirmed identities [12]. The 13 Rabby builds are the sharpest case: the theft happens upstream of the wallet's own encryption, so the user's passphrase hygiene is irrelevant.
On timing, Socket says the campaign has run since at least March 2026 and continued into August [13], with Mozilla signing records for the original 59 analysed versions spanning March 9 to August 3 and activity peaking in April and late July [14]. That is a 147-day signing window [15]. Investigation through mid-August turned up 18 more campaign-linked identities, expanding the tracked set to 77, with several still live when Socket reported them to Mozilla's security team [16][21]. Socket is calling the cluster "Offside Wallet Theft Factory" and says attribution remains under investigation, with the available evidence not establishing that a single actor controls every extension [19][20].
The operational lesson is narrow and worth taking literally. Review approves a build; the identity persists across builds. Socket's own linkage criteria include version histories in which stable Firefox IDs move from shell or utility builds into wallet malware [24], so an allowlist keyed on add-on ID alone inherits that gap. If you allowlist, pin versions where your management tooling supports it, block install from any source other than your own approved set, and alert on version changes to approved extensions rather than only on new installs. The remaining 31 confirmed identities had no sports API at all and were malicious from the builds analysed [5], so the repurposing route is one path in, not the only one [6].
Socket also notes the asymmetry that makes this worth budget: a wallet extension does not need to survive long, because exposure of a recovery phrase or private key is immediate and irreversible [22]. Detection latency measured in days is a loss.