Offside Wallet Theft Factory: scale and timeline
The Socket Threat Research team identified a coordinated campaign it calls Offside Wallet Theft Factory that has been active since March 2026. Socket’s analysis shows 77 related Firefox browser add‑ons with shared source‑code and infrastructure overlaps; of those, 40 extensions are confirmed malicious and 37 form a coordinated "multi‑sport score‑shell" operation. The activity has not been attributed to any known threat actor or group.
Tactics: how wallets are stolen
Socket and Boychenko document two primary theft methods. Some extensions remotely load a fake wallet page to harvest secrets; others bake wallet‑stealing functionality directly into the extension build. Across the 40 confirmed malicious extensions, the observed payloads and behaviors break down as follows: 15 capture recovery phrases, private keys, and other wallet secrets and exfiltrate them via Cloudflare Workers; 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption; five extensions capture credentials and clipboard data through hard‑coded command and control (C2) infrastructure; and seven use threat‑actor‑controlled Supabase projects as remote switches to serve phishing or decoy content dynamically.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageInfrastructure: Supabase projects, Cloudflare Workers, and modified Rabby Wallet builds
Socket’s report emphasizes that malicious functionality is sometimes separated from the browser extension itself and hosted on cloud infrastructure. Seven of the malicious extensions query Supabase projects controlled by the threat actors to enable or disable remote pages and phishing content. Fifteen extensions send stolen recovery phrases and private keys to Cloudflare Workers. A distinct cluster — thirteen builds — are based on modified Rabby Wallet code and are observed to exfiltrate serialized keyrings before those keyrings are encrypted locally. This division of labor — lightweight extension front ends with remote switching and cloud exfiltration — supports rapid reuse and makes individual malicious builds cheaper and easier to rotate.
Sports-score shells, repurposed identities, and the Firefox Add‑ons ecosystem
Many of the 77 related add‑ons started life on the official Firefox extensions marketplace as sports score or benign utility shells. Socket labels 37 extensions a coordinated "multi‑sport score‑shell operation"; these deceptive builds span football, basketball, NBA, and hockey and even embed a hard‑coded credential for the legitimate API‑Sports service while marketing unrelated features such as password generation, dark mode, VPN access, currency conversion, screenshot capture, and note‑taking. Historical versions of nine of the confirmed malicious identities used sports‑score shells before later versions under the same Firefox IDs were repurposed into wallet‑stealing extensions. Socket found another 31 confirmed malicious identities that lack the sports API integration but contain confirmed wallet‑ or credential‑stealing functionality.
Examples and naming patterns
Socket shares multiple extension names and associated publisher IDs that illustrate repurposing and disguise. Examples listed in the analysis include:
- Safe-Themes - Browser Extension (bliss-heaven@webbrol.com)
- Rabbit For Desktop (bright-save-feed@tabtools.org)
- ℞ab␢y Wa❘Iet (flex-clock-dash@extrakits.com)
- Rabb-Walӏet CryptoPortfolio (free-note-bolt@webtools.co)
- RABB-Walӏet Web3 & EVM (safe-stat-pure@proaddons.net)
- Rabbit/WALLET - EVM (sharp-stat-gear@netplugs.net)
Boychenko notes the operational economics driving persistence: "A single successful installation can expose a recovery phrase, private key, or wallet state worth far more than the cost of repeatedly publishing disposable extensions." Actor behaviors observed include rotating names and IDs, repurposing existing extension identities, cloning code, and separating malicious functionality across extensions, remote pages, and cloud infrastructure — all tactics that make repeated publication cheap and scalable.
What this means for security teams, platform maintainers, and end users
- Security teams and technologists: Watch for exfiltration patterns tied to Cloudflare Workers and Supabase endpoints, and for modified builds of known wallet software such as Rabby Wallet that serialize keyrings before encryption.
- Platform maintainers (Firefox Add‑ons ecosystem): The repurposing of existing extension identities under the same Firefox IDs and the use of sports‑score shells as camouflage highlights a need to track version histories and publishing artifacts alongside current behavior.
- End users and wallet holders: A single installation of one of these confirmed malicious extensions can expose recovery phrases or private keys; users should be wary of extensions advertising unrelated utilities (sports scores, dark mode, currency conversion) and of extensions that request Web3 or wallet permissions.
Socket’s findings lay out a modular, low‑cost campaign that leverages cloud services and marketplace mechanics to scale thefts of high‑value wallet secrets. Active since March 2026 and un‑attributed, Offside Wallet Theft Factory demonstrates how disposable code and rotated identities can turn a single browser extension install into a catastrophic loss for a cryptocurrency wallet holder — and it leaves open a practical question for defenders: if the same Firefox ID can host benign and then malicious builds, how must review and telemetry adapt to keep pace?
Original reporting: The Hacker News — 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets




