Thehackernews
Coordinated Campaign of Malicious Firefox Extensions Targets Crypto Users
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A coordinated campaign has been launched against Firefox users, involving malicious extensions that impersonate cryptocurrency wallets and tools. These extensions are designed to extract sensitive information, including recovery phrases, private keys, and clipboard data. The operation has been active since at least March 2026 and has affected a significant number of users, with reports indicating at least 40 different malicious extensions. Victims are at risk of losing their digital assets and online accounts due to these deceptive add-ons. The malicious actors are leveraging Cloudflare Workers to facilitate the exfiltration of data. Users are advised to be cautious and verify the legitimacy of extensions before installation.
Key Points: • At least 40 malicious Firefox extensions are targeting cryptocurrency users. • The extensions can steal sensitive information like private keys and recovery phrases. • The campaign has been active since March 2026, posing a significant risk to digital assets.