Article Details

Scrape Timestamp (UTC): 2025-07-03 10:58:07.988

Source: https://thehackernews.com/2025/07/over-40-malicious-firefox-extensions.html

Original Article Text

Click to Toggle View

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Stealing User Assets. Cybersecurity researchers have uncovered over 40 malicious browser extensions for Mozilla Firefox that are designed to steal cryptocurrency wallet secrets, putting users' digital assets at risk. "These extensions impersonate legitimate wallet tools from widely-used platforms such as Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, MyMonero, Bitget, Leap, Ethereum Wallet, and Filfox," Koi Security researcher Yuval Ronen said. The large-scale campaign is said to have been ongoing since at least April 2025, with new extensions uploaded to the Firefox Add-ons store as recently as last week. The identified extensions have been found to artificially inflate their popularity, adding hundreds of 5-star reviews that go far beyond the total number of active installations. This strategy is employed to give them an illusion of authenticity, making it seem like they are widely adopted and tricking unsuspecting users into installing them. Another tactic adopted by the threat actor to bolster trust involves passing off these add-ons as legitimate wallet tools, using the same names and logos. The fact that some of the actual extensions were open-source allowed the attackers to clone their source code and inject their own malicious functionality to extract wallet keys and seed phrases from targeted websites and exfiltrate them to a remote server. The rogue extensions have also been found to transmit the victims' external IP addresses. Unlike typical phishing scams that rely on fake websites or emails, these extensions operate inside the user's browser—making them far harder to detect or block with traditional endpoint tools. "This low-effort, high-impact approach allowed the actor to maintain expected user experience while reducing the chances of immediate detection," Ronen said. The presence of Russian language comments in the source code as well as metadata obtained from a PDF file retrieved from the command-and-control (C2) server used for the activity points to a Russian-speaking threat actor group. All the identified add-ons with the exception of MyMonero Wallet have since been taken down by Mozilla. Last month, the browser maker said it has developed an "early detection system" to detect and block scam crypto wallet extensions before they gain popularity among users and are used to steal users' assets by tricking them into entering their credentials. To mitigate the risk posed by such threats, it's advised to install extensions only from verified publishers and vet them to ensure that they don't silently change their behavior post-installation.

Daily Brief Summary

MALWARE // Over 40 Firefox Extensions Found Stealing Cryptocurrency Wallets

Cybersecurity researchers identified over 40 harmful Mozilla Firefox extensions designed to steal cryptocurrency wallet details.

These extensions mimic well-known wallet tools like Coinbase, MetaMask, and others, using fake reviews to appear legitimate.

Launched since at least April 2025, the malicious campaign uses cloned open-source extensions with added harmful code.

The malicious extensions steal keys and seed phrases, transmitting them along with users' IP addresses to a remote server.

Evidence suggests a Russian-speaking group is behind this high-impact, low-effort cyber attack.

Mozilla has taken down nearly all related extensions and introduced an "early detection system" to block such scam extensions.

Users are urged to download extensions from verified publishers and regularly check for any unauthorized changes.