Cybersecurity researchers have uncovered a widespread campaign involving over 40 malicious Firefox extensions designed to pilfer cryptocurrency wallet secrets. These extensions, masquerading as trusted tools, target users of major wallet brands such as Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox.

A Sophisticated Impersonation and Manipulation Strategy

The fake extensions mimic legitimate wallet tools, adopting the same names, logos, and even user interfaces. To bolster credibility, they deploy artificial popularity tactics—injecting hundreds of 5‑star reviews and downloads, vastly inflating user counts. This social engineering method lures users into trusting and installing extensions that appear well‑established.

Malicious Code Hidden in Cloned Source

Attackers cloned open‑source wallet extension code, then injected malicious payloads. Once installed, these extensions actively hunt for wallet keys and seed phrases. Upon capturing these sensitive credentials, they exfiltrate the data—along with victims’ external IP addresses—to remote command‑and‑control (C2) servers.

Unlike conventional phishing schemes that rely on fake websites or malicious emails, these extension‑based attacks unfold directly within the user’s browser, evading typical endpoint detection tools. The stealthy in‑browser execution maintains expected behavior, making the extortion difficult to detect immediately.

Russian-Speaking Threat Actor Likely Behind It

Analysis of the embedded code, including Russian-language comments and metadata extracted from a PDF on the C2 server, suggests the group operating these extensions is likely Russian-speaking . While attribution remains tentative, this linguistic footprint provides key insight into its origins.

Timeline: From April 2025 to Recent Take-Downs

The campaign has been active since at least April 2025, with new malicious extensions being published as recently as last week. In response, Mozilla has taken down all identified extensions except for “MyMonero Wallet,” which at the time had not yet been removed. Last month, Mozilla announced the creation of a proactive “early detection system” aimed at identifying and blocking fraudulent crypto‑wallet extensions before they gain traction.

Why Browser Extensions Are a Prime Attack Vector

  • Deep Access: Browser extensions can access web content, read and modify page data, and interact with browser storage—making them potent attack vectors when abused.
  • Stealth Operations: Once installed, malicious extensions run quietly in the background, bypassing antivirus detection more effectively than email or web‑based phishing.
  • Social Engineering at Scale: By cloning reputable extensions and fabricating legitimacy via reviews and downloads, attackers leverage trust to deceive en masse.

Protective Measures for Users

  1. Install from Verified Publishers: Always double‑check the publisher’s name, digital signature, and review history before installing.
  2. Review Permissions Carefully: Be cautious of extensions requesting access to clipboard, DOM elements, or cross-site scripting.
  3. Audit Installed Extensions: Conduct periodic checks of your browser’s extension list. Remove anything unfamiliar or outdated.
  4. Update Regularly: Keep your browser and extensions updated. Mozilla’s early detection initiative is expected to mitigate future threats.

What Mozilla Is Doing

Mozilla has permanently removed identified malicious extensions and announced plans for an enhanced vetting system. This includes automated tools designed to detect cloned wallets and anomalies in review or installation patterns. The initiative aims to prevent scam extensions from reaching users in the first place .


Final Thoughts

This incident underscores the urgent need for vigilance when adding browser extensions—especially those requesting access to sensitive data like cryptocurrency wallets. The attackers’ ability to replicate trusted software, manipulate metadata and user reviews, and quietly exfiltrate data illustrates an advanced, low-effort, high-impact attack model.

For users and organizations alike, stronger security hygiene—inspecting publishers, vetting permissions, and routinely auditing extensions—is essential. Meanwhile, Mozilla’s evolving protections offer hope that similar campaigns will be detected and disrupted before they spread further.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *