Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Web3 and cryptocurrency wallet users
Incident: Deployment of 40 malicious Firefox extensions designed to steal cryptocurrency wallet secrets.
Impact: Theft of private keys and recovery phrases leading to total loss of cryptocurrency funds.
Attacker: Unidentified threat actors
Analysis: Threat actors are employing a ‘bait-and-switch’ tactic, initially publishing benign sports-themed extensions before updating them with wallet-stealing payloads. The campaign leverages cloud infrastructure like Cloudflare Workers and Supabase to exfiltrate private keys and recovery phrases. This scalable approach allows attackers to rotate identities quickly to evade detection on the official marketplace.
Recommendations: Audit installed browser extensions and remove any untrusted or unnecessary add-ons.; Avoid installing Web3 wallets via browser extension stores; download directly from official developer sites.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source