Login
Sign Up
Woofun AI reports that a supply-chain attack involving 40 malicious Firefox add-ons drained crypto wallets, with nine identities previously distributing sports-score tools. The threat actors leveraged these legitimate fronts to inject code capable of stealing sensitive wallet data.
Woofun AI data shows. The campaign operated from at least March into August, with Mozilla signing records for the original 59 versions analyzed by Socket running from March 9 through Aug. 3. Activity clustered in April and late July, while Socket's version histories confirmed that the nine affected IDs had earlier hosted benign sports utilities before pivoting to malicious distribution.
A recovery phrase or private key can restore a wallet elsewhere, and a serialized keyring similarly exposes the wallet's account state before encryption can protect it. Anyone who entered one of those secrets, or used an affected build that transmitted its keyring, should move remaining assets to a fresh crypto wallet created from a new recovery phrase. Users exposed only to the credential-and-clipboard group should change affected passwords, terminate active sessions where possible, and verify copied destination addresses. Wallet keys need rotation when wallet-secret or keyring exposure occurred.
Socket documented theft capability and exfiltration infrastructure, but did not identify confirmed victims, attributable transactions, or a campaign loss total. This lack of quantified damage underscores the stealth nature of the operation, leaving the full financial impact unknown.