Coordinated Campaign of Malicious Firefox Extensions Targets Crypto Users

Coordinated Campaign of Malicious Firefox Extensions Targets Crypto Users

First seen 20 Aug 2026, 12:22 UTC ThehackernewsCybersecuritynews 79% similarity 66.0

Article Content

Browse articles
ThreatCluster

A coordinated campaign has been launched against Firefox users, involving malicious extensions that impersonate cryptocurrency wallets and tools. These extensions are designed to extract sensitive information, including recovery phrases, private keys, and clipboard data. The operation has been active since at least March 2026 and has affected a significant number of users, with reports indicating at least 40 different malicious extensions. Victims are at risk of losing their digital assets and online accounts due to these deceptive add-ons. The malicious actors are leveraging Cloudflare Workers to facilitate the exfiltration of data. Users are advised to be cautious and verify the legitimacy of extensions before installation.

Key Points: • At least 40 malicious Firefox extensions are targeting cryptocurrency users. • The extensions can steal sensitive information like private keys and recovery phrases. • The campaign has been active since March 2026, posing a significant risk to digital assets.

ThreatCluster AI How this analysis works

Timeline

2026-03-01
Malicious Firefox extensions campaign began
A coordinated effort to distribute fake cryptocurrency wallet extensions started targeting users.
Cybersecuritynews
2026-08-20
Cybersecurity articles published
Two articles reported on the ongoing threat posed by malicious Firefox extensions targeting crypto users.
Thehackernews
Recent
Users warned about malicious extensions
Firefox users are advised to verify the legitimacy of extensions to avoid falling victim to the campaign.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story