← Terug naar overzicht

Socket has expanded its security coverage to Firefox, scanning over 97,000 extensions in Mozilla's official directory for malicious behavior, risky updates, and supply chain threats. Research identified 77 linked malicious Firefox extension identities active from March through August 2026, with 40 confirmed malicious and 37 deceptive shells. These extensions delivered wallet-phishing pages, stole crypto recovery phrases and private keys, and exfiltrated credentials and clipboard contents. A key attack pattern involved legitimate-looking extensions being repurposed via automatic updates to deliver malware without triggering new permission prompts. Some malicious extensions transitioned from sports-score or utility tools to Rabby-style wallet stealers. Socket's platform provides visibility, threat detection, update monitoring, and ecosystem context to help enterprise security teams track extension behavior changes. The Firefox extension protection feature is now available in experimental status for Socket enterprise customers.

Technical details

Socket identified 77 linked Firefox extension identities active from at least March through August 2026, confirming 40 as malicious and 37 as deceptive sports-score shells connected through shared code, infrastructure, and version histories. Malicious extensions delivered remotely controlled wallet-phishing pages, captured recovery phrases and private keys, exfiltrated wallet keyrings, and stole credentials and clipboard contents. One remote-loader cluster requested only 'storage' and 'tabs' permissions, demonstrating how serious risk can be present without alarming permission sets. Nine confirmed malicious extension identities had previously shipped as sports-score shells before being repurposed as wallet stealers. Others transitioned from utility names (e.g., Visited Link Marker, Flow Pomodoros) to Rabby-style wallets carrying credential and clipboard-stealing code. The attack vector exploits Firefox's automatic update mechanism: extensions can change behavior within existing permissions without triggering a new permission prompt, allowing malicious updates to be silently delivered to users who already granted permissions. The WebExtensions model (introduced in Firefox 57 in 2017) provides capabilities such as reading/modifying web pages, accessing browser tabs, interacting with clipboard, observing browsing activity, and communicating with external services.

Mitigation steps

1. Use Socket's proactive browser extension security coverage to gain visibility into Firefox extensions deployed across the organization. 2. Monitor extension version histories and compare releases under the same extension identity to surface meaningful changes in permissions, code, network activity, and behavior. 3. Do not rely solely on permission review; analyze code, metadata, infrastructure, and version history together to understand actual behavior. 4. Identify which Firefox extensions are present in the organization, what they can access, and whether they have changed since approval. 5. Flag extensions that load remote code or content even if they request minimal permissions. 6. Investigate extensions connected to shared infrastructure, reused code, or coordinated campaigns. 7. Enterprise customers should contact Socket account teams to enable experimental Firefox extension coverage. 8. Evaluate update monitoring alerts for new risk introduced by extension updates, particularly those involving network endpoints, obfuscation, or impersonation behaviors.

Affected products

  • 100+ extensions scanned)
  • Cryptocurrency wallets targeted via malicious extensions (Rabby-style wallets)
  • Firefox 57+)
  • Firefox Extensions on addons.mozilla.org (97
  • Mozilla Firefox (all versions using WebExtensions model

IOC's

Extensions impersonating Rabby wallet, Extension names: Visited Link Marker (repurposed malicious), Extension names: Flow Pomodoros (repurposed malicious), Extensions requesting only 'storage' and 'tabs' permissions used as remote loaders, Sports-score shell extensions linked to wallet-stealing malware via shared code and infrastructure, Remote-controlled wallet-phishing page delivery via extensions, Clipboard monitoring and credential theft behavior in extensions, Wallet keyring exfiltration behavior, Recovery phrase and private key capture behavior

Categories

  • Data Breach & Exfiltration
  • Ransomware & Malware
  • Supply Chain & Dependencies
  • Web Technologies