According to a report by BleepingComputer on July 2, over 40 malicious extensions have been found in the official Firefox extension store, impersonating well-known Crypto Assets Wallets, including counterfeit Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero.
The security company Koi Security discovered that these malicious extensions monitor user input, steal wallet mnemonics and private keys, and transmit the data to servers controlled by the attackers. Many of the extensions are cloned versions of legitimate open-source wallets, but with added malicious code. Attackers establish trust by using real brand logos and a large number of fake five-star reviews.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Koi Security: Over 40 counterfeit Wallet extension programs appear in the Firefox app store
According to a report by BleepingComputer on July 2, over 40 malicious extensions have been found in the official Firefox extension store, impersonating well-known Crypto Assets Wallets, including counterfeit Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, OKX, Keplr, and MyMonero.
The security company Koi Security discovered that these malicious extensions monitor user input, steal wallet mnemonics and private keys, and transmit the data to servers controlled by the attackers. Many of the extensions are cloned versions of legitimate open-source wallets, but with added malicious code. Attackers establish trust by using real brand logos and a large number of fake five-star reviews.