16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys during wallet imports. Disguised as wallet portals, desktop utilities, and browser tools, the packages attempt to transmit secrets to attacker-controlled Cloudflare Workers. Mozilla had unpublished the extensions by October 5, 2026, according to Socket’s October 7 report. Fifteen packages contain […]
Read the original article:
