Wallet Assassins in Browser: 40 Malicious Firefox Extensions Are Stealing Your Private Keys
- A security research team discovered at least 40 high-risk malicious extensions in Mozilla Firefox's official extension store.
- These extensions are disguised as mainstream Web3 wallets and are designed to steal users' mnemonic phrases and private keys.
- The attack has been active since March 2026 and is linked to 37 other shell plugins disguised as harmless tools.
- Attackers use a remote control mechanism to activate malicious logic after users install the extensions.
- Browser extensions have high permissions, making them a significant risk for crypto wallet users.
On August 20, 2026, a security research team named Socket published a report detailing a significant security threat involving at least 40 malicious extensions available in Mozilla Firefox's official extension store. These extensions are disguised as legitimate Web3 wallets, tricking users into inputting sensitive information such as mnemonic phrases and private keys, which are then stolen by the attackers.
The investigation revealed that this attack campaign has been ongoing since March 2026 and is part of a larger network of 77 interconnected code repositories. Attackers utilize a sophisticated method of creating and modifying extensions in bulk, allowing them to bypass official reviews by initially listing the extensions without malicious code.
Browser extensions have extensive permissions that can allow malicious actors to intercept and modify user data, making them a prime target for cybercriminals. Users are advised to regularly check their installed extensions to avoid falling victim to these types of attacks.
浏览器中的钱包窃贼:40个恶意Firefox扩展正在窃取您的私钥
2026年8月20日,安全研究团队Socket发布了一份报告,详细介绍了涉及至少40个恶意扩展的重大安全威胁,这些扩展在Mozilla Firefox的官方扩展商店中可用。这些扩展伪装成合法的Web3钱包,欺骗用户输入助记词和私钥等敏感信息,然后被攻击者窃取。
调查显示,这一攻击活动自2026年3月以来一直在进行,并且是77个互联代码库更大网络的一部分。攻击者利用批量创建和修改扩展的复杂方法,使他们能够通过最初不包含恶意代码的方式绕过官方审核。
浏览器扩展具有广泛的权限,可以允许恶意行为者拦截和修改用户数据,使其成为网络犯罪分子的主要目标。建议用户定期检查已安装的扩展,以避免成为此类攻击的受害者。