Over 40 Malicious Firefox Extensions Exploit Cryptocurrency Wallets to Steal User Assets

Published:

spot_img

Rising Threats: Malicious Extensions Targeting Firefox Users

Overview of the Malicious Extensions

Recent revelations from cybersecurity experts have unveiled a troubling trend: over 40 harmful browser extensions for Mozilla Firefox have been discovered, all aimed at stealing cryptocurrency wallet information from unsuspecting users. This alarming discovery places users’ digital assets at significant risk, prompting immediate concern within the cybersecurity community.

Methods of Deception

These malicious extensions cleverly disguise themselves as legitimate tools from popular cryptocurrency platforms, including Coinbase, MetaMask, Trust Wallet, and Phantom. The lead researcher from Koi Security, Yuval Ronen, noted that these extensions have been part of a large-scale campaign that likely originated in April 2025.

Ongoing Campaign

The scope of this campaign is worrisome; new extensions have even been uploaded to the Firefox Add-ons store as recently as last week. This demonstrates not only the persistence of the attackers but also their ability to continuously target users. It highlights the importance of vigilance among those involved in the cryptocurrency space.

Fake Popularity Tactics

To lure users into downloading these malicious extensions, the attackers have employed tactics to artificially enhance their perceived popularity. They’ve added numerous five-star reviews that exceed the actual number of installations, creating an illusion of widespread adoption. This deceptive practice is designed to manipulate users into believing they are opting for a trusted tool, making them more likely to install the extension.

Impersonation of Legitimate Brands

In an even more troubling twist, these extensions often mimic well-known wallet tools by usurping their names and logos. By doing so, they trick users into a false sense of security, capitalizing on the reputation of legitimate services. This strategy sets a trap for users who are unaware that they are engaging with fraudulent software.

Technical Exploits

The attackers have demonstrated a clear understanding of the technologies they are exploiting. By cloning open-source wallet extensions, they have injected malicious code designed to steal sensitive information such as wallet keys and seed phrases. This information is then sent to a remote server, putting victims’ assets in jeopardy. Additionally, these rogue extensions are capable of transmitting users’ external IP addresses, further compromising their security.

Challenges in Detection

What makes these extensions particularly dangerous is their method of operation. Unlike traditional phishing scams that often utilize fake websites or emails, these malicious extensions operate directly within users’ browsers. This stealthy approach greatly complicates detection and thwarting efforts, as standard endpoint security tools struggle to identify threats embedded so deeply in the browser’s architecture.

Language Indicators

Investigators found Russian language comments in the source code along with metadata linked to a PDF file retrieved from the control server. These clues suggest a Russian-speaking threat actor group is behind this malicious campaign, raising flags about the level of sophistication involved.

Response from Mozilla

In response to these threats, Mozilla has taken swift action. All identified malicious add-ons, with the exception of MyMonero Wallet, have been removed from the Firefox Add-ons store. Last month, Mozilla announced the development of an "early detection system" aimed at identifying and blocking fraudulent extensions before they can mislead users and facilitate asset theft.

Best Practices for Users

To safeguard against such threats, users are strongly encouraged to download browser extensions only from verified publishers. Additionally, they should remain vigilant about the behavior of any extensions after installation, ensuring that they do not deviate from their intended functionality over time. Exercising caution when adding features to the browser can make a substantial difference in personal cybersecurity.

In an evolving digital landscape, the risk of falling victim to malicious extensions underscores the importance of proactive security measures. Users must stay informed and cautious as they navigate the world of digital assets.

spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...