Rising Threats: Malicious Extensions Targeting Firefox Users
Overview of the Malicious Extensions
Recent revelations from cybersecurity experts have unveiled a troubling trend: over 40 harmful browser extensions for Mozilla Firefox have been discovered, all aimed at stealing cryptocurrency wallet information from unsuspecting users. This alarming discovery places users’ digital assets at significant risk, prompting immediate concern within the cybersecurity community.
Methods of Deception
These malicious extensions cleverly disguise themselves as legitimate tools from popular cryptocurrency platforms, including Coinbase, MetaMask, Trust Wallet, and Phantom. The lead researcher from Koi Security, Yuval Ronen, noted that these extensions have been part of a large-scale campaign that likely originated in April 2025.
Ongoing Campaign
The scope of this campaign is worrisome; new extensions have even been uploaded to the Firefox Add-ons store as recently as last week. This demonstrates not only the persistence of the attackers but also their ability to continuously target users. It highlights the importance of vigilance among those involved in the cryptocurrency space.
Fake Popularity Tactics
To lure users into downloading these malicious extensions, the attackers have employed tactics to artificially enhance their perceived popularity. They’ve added numerous five-star reviews that exceed the actual number of installations, creating an illusion of widespread adoption. This deceptive practice is designed to manipulate users into believing they are opting for a trusted tool, making them more likely to install the extension.
Impersonation of Legitimate Brands
In an even more troubling twist, these extensions often mimic well-known wallet tools by usurping their names and logos. By doing so, they trick users into a false sense of security, capitalizing on the reputation of legitimate services. This strategy sets a trap for users who are unaware that they are engaging with fraudulent software.
Technical Exploits
The attackers have demonstrated a clear understanding of the technologies they are exploiting. By cloning open-source wallet extensions, they have injected malicious code designed to steal sensitive information such as wallet keys and seed phrases. This information is then sent to a remote server, putting victims’ assets in jeopardy. Additionally, these rogue extensions are capable of transmitting users’ external IP addresses, further compromising their security.
Challenges in Detection
What makes these extensions particularly dangerous is their method of operation. Unlike traditional phishing scams that often utilize fake websites or emails, these malicious extensions operate directly within users’ browsers. This stealthy approach greatly complicates detection and thwarting efforts, as standard endpoint security tools struggle to identify threats embedded so deeply in the browser’s architecture.
Language Indicators
Investigators found Russian language comments in the source code along with metadata linked to a PDF file retrieved from the control server. These clues suggest a Russian-speaking threat actor group is behind this malicious campaign, raising flags about the level of sophistication involved.
Response from Mozilla
In response to these threats, Mozilla has taken swift action. All identified malicious add-ons, with the exception of MyMonero Wallet, have been removed from the Firefox Add-ons store. Last month, Mozilla announced the development of an "early detection system" aimed at identifying and blocking fraudulent extensions before they can mislead users and facilitate asset theft.
Best Practices for Users
To safeguard against such threats, users are strongly encouraged to download browser extensions only from verified publishers. Additionally, they should remain vigilant about the behavior of any extensions after installation, ensuring that they do not deviate from their intended functionality over time. Exercising caution when adding features to the browser can make a substantial difference in personal cybersecurity.
In an evolving digital landscape, the risk of falling victim to malicious extensions underscores the importance of proactive security measures. Users must stay informed and cautious as they navigate the world of digital assets.


