Security firm Socket linked 77 Firefox extension identities to a campaign called the Offside Wallet Theft Factory, with 40 confirmed as malicious. These extensions impersonate popular wallets including OKX, Rabby Wallet and TronLink to harvest recovery phrases and private keys. Nine of them were initially published as sports score applications before later updates transformed them into wallet-stealing tools. Users who entered a recovery phrase into one of these extensions should treat it as permanently compromised and move their funds to a new wallet. The campaign ran from March 9 to August 3, with several extensions still live when Socket reported them.
Source: Read the original article

