Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Malicious Firefox Add‑Ons Harvest Crypto Wallet Seed Phrases and Browser Credentials

A campaign of malicious Firefox extensions, dubbed the Offside Wallet Theft Factory, has been stealing cryptocurrency seed phrases and browser passwords by toggling behavior through a remote Supabase database. The incident highlights gaps in access‑control policies and the need for continuous monitoring, a core SOC 2 readiness focus.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 bitdefender.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bitdefender.com

Malicious Firefox Add‑Ons Harvest Crypto Wallet Seed Phrases and Browser Credentials

What Happened — Researchers at Socket identified a campaign of malicious Firefox extensions, dubbed the “Offside Wallet Theft Factory,” that silently query a Supabase‑hosted database and, when instructed, present a fake wallet import page to harvest cryptocurrency seed phrases and browser‑saved passwords. Out of 77 linked add‑ons, 40 were confirmed to exfiltrate credentials; the remaining 37 shared code and infrastructure, indicating a broader supply‑chain of malicious extensions.

Why It Matters for Compliance & Audit Readiness

  • The scenario exemplifies a failure of access control and policy enforcement that SOC 2 Trust Services Criteria (CC6.1 – Logical Access Controls) are designed to prevent and evidence.
  • Continuous monitoring of third‑party software and maintaining an auditable inventory of approved browser extensions provide the defensible trail auditors expect.
  • Security awareness training that covers the risk of low‑permission extensions directly supports the SOC 2 Security principle (CC7.1).

Who Is Affected – Primarily users of cryptocurrency wallets and any organization whose employees rely on Firefox extensions for productivity (financial services, fintech, SaaS, and broader enterprise environments).

Recommended Actions

  • Update your asset‑management policy to require approval and periodic review of all browser extensions.
  • Enforce least‑privilege permissions and block installation of unsigned or unverified add‑ons via endpoint‑security controls.
  • Incorporate extension‑risk scenarios into your security awareness curriculum and conduct phishing‑style simulations that include malicious add‑on prompts.
  • Deploy continuous monitoring tools that log extension installations and generate alerts for anomalous behavior. Source: Bitdefender Blog

Technical Notes

  • Attack vector: malicious browser add‑on (malware) leveraging a remote Supabase database to toggle behavior without store updates.
  • Data types stolen: cryptocurrency wallet seed/recovery phrases, saved browser passwords, and potentially other credential stores.
  • Observed timeline: active since at least March 2026; 77 extensions linked, 40 confirmed malicious. Source: Bitdefender Blog
📰 Original Source
https://www.bitdefender.com/en-us/blog/hotforsecurity/malicious-firefox-add-ons-stealing-cryptowallet-seed-phrases-browser-credentials ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →