ZeroHour

Search: “Firefox”

1,606 stories

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Socket found 40 malicious Firefox extensions impersonating OKX, Rabby Wallet, and TronLink to steal cryptocurrency wallet recovery phrases and private keys.

The Socket Threat Research team identified 40 malicious Firefox extensions masquerading as Web3 products including OKX, Rabby Wallet, and TronLink, part of a broader set of 77 add-ons sharing source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, has been active since March 2026 and remains unattributed. Of the 40 confirmed malicious extensions, 15 capture recovery phrases and private keys exfiltrated through Cloudflare Workers, 13 modified Rabby Wallet builds exfiltrate serialized keyrings before local encryption, seven use attacker-controlled Supabase projects as remote switches, and five capture credentials and clipboard data via hard-coded C2. Some extensions began as sports score or utility shells before being repurposed into wallet stealers under the same Firefox ID.

The Hacker News · 27d agoMalware in the wild

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla revoked the Firefox and Thunderbird Linux RPM signing subkey after an unencrypted copy landed in a private repo; no unauthorized access found.

Mozilla revoked the OpenPGP signing subkey (fingerprint 09BE ED63 F346 2A2D FFAB 3B87 5ECB 6497 C1A2 0256) used for Firefox and Thunderbird Linux downloads after an unencrypted copy was committed to one of its private repositories, citing reason code 2, 'key material has been compromised.' Audit records showed no sign of unauthorized access, and a replacement subkey (827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3) valid until August 5, 2028 was published. Users who verify signatures manually or install from Mozilla RPM packages may need to import the new key and remove the old one. The rotation came roughly seven months ahead of Mozilla's usual two-year subkey cycle.

The Hacker News · Aug 11, 2026Data breach