Crypto Wallet Clones Target Firefox Users in Malware Campaign

Over 40 fake Firefox extensions mimicking popular crypto wallets are stealing user credentials in an active phishing campaign suspected to originate from a Russian-speaking group.
Malicious extensions impersonate popular wallets
More than 40 fake Mozilla Firefox extensions have been linked to a large-scale phishing campaign aimed at stealing cryptocurrency. According to cybersecurity firm Koi Security, the malicious extensions impersonate wallets like MetaMask, Coinbase, Trust Wallet, Phantom, Exodus, OKX, MyMonero, Bitget, and others. Once installed, these extensions steal users’ wallet credentials and send them to a remote server controlled by the attackers.
Campaign remains active with frequent updates
Koi Security reports that the campaign has been active since at least April, with the latest malicious extensions uploaded just last week. The attackers use fake reviews, branding, and identical names to the real wallets to gain user trust. In some cases, they cloned open-source code from official extensions, adding malicious scripts to preserve the user experience while executing the attack.
Russian-speaking threat actor suspected
While attribution remains tentative, Koi Security noted signs suggesting the campaign might be orchestrated by a Russian-speaking threat group. Evidence includes Russian-language comments in the code and metadata from files retrieved from the attackers’ servers. Koi Security recommends installing extensions only from verified publishers, treating them as full software assets, and monitoring for unusual behaviors or unexpected updates to reduce the risk of compromise.

