Malicious Firefox Add‑Ons Harvest Crypto Wallet Seed Phrases and Browser Credentials
What Happened — Researchers at Socket identified a campaign of malicious Firefox extensions, dubbed the “Offside Wallet Theft Factory,” that silently query a Supabase‑hosted database and, when instructed, present a fake wallet import page to harvest cryptocurrency seed phrases and browser‑saved passwords. Out of 77 linked add‑ons, 40 were confirmed to exfiltrate credentials; the remaining 37 shared code and infrastructure, indicating a broader supply‑chain of malicious extensions.
Why It Matters for Compliance & Audit Readiness
- The scenario exemplifies a failure of access control and policy enforcement that SOC 2 Trust Services Criteria (CC6.1 – Logical Access Controls) are designed to prevent and evidence.
- Continuous monitoring of third‑party software and maintaining an auditable inventory of approved browser extensions provide the defensible trail auditors expect.
- Security awareness training that covers the risk of low‑permission extensions directly supports the SOC 2 Security principle (CC7.1).
Who Is Affected – Primarily users of cryptocurrency wallets and any organization whose employees rely on Firefox extensions for productivity (financial services, fintech, SaaS, and broader enterprise environments).
Recommended Actions
- Update your asset‑management policy to require approval and periodic review of all browser extensions.
- Enforce least‑privilege permissions and block installation of unsigned or unverified add‑ons via endpoint‑security controls.
- Incorporate extension‑risk scenarios into your security awareness curriculum and conduct phishing‑style simulations that include malicious add‑on prompts.
- Deploy continuous monitoring tools that log extension installations and generate alerts for anomalous behavior. Source: Bitdefender Blog
Technical Notes
- Attack vector: malicious browser add‑on (malware) leveraging a remote Supabase database to toggle behavior without store updates.
- Data types stolen: cryptocurrency wallet seed/recovery phrases, saved browser passwords, and potentially other credential stores.
- Observed timeline: active since at least March 2026; 77 extensions linked, 40 confirmed malicious. Source: Bitdefender Blog