• News/
  • https://www.bleepingcomputer.com/news/security/wave-of-150-crypto-draining-extensions-hits-firefox-add-on-store/

Wave of 150 crypto-draining extensions hits Firefox add-on store

BleepingComputer
·
Bill Toulas
·
Published Aug 7, 2025
·
Updated

A malicious campaign dubbed 'GreedyBear' has snuck onto the Mozilla add-ons store, targeting Firefox users with 150 malicious extensions and stealing an estimated $1,000,000 from unsuspecting victims. The campaign, discovered and documented by Koi Security, impersonates cryptocurrency wallet extensions from well-known platforms such as MetaMask, TronLink, and Rabby. These extensions are uploaded in a benign form initially, to be accepted by Firefox, and accumulate fake positive reviews. At a later phase, the publishers strip out the original branding and replace it with new names and logos while also injecting malicious code to steal users' wallet credentials and IP addresses. The malicious code acts as a keylogger, capturing input from form fields or within displayed popups, which are then sent to the attacker's server. "The weaponized extensions captures wallet credentials directly from user input fields within the extension’s own popup interface, and exfiltrate them to a remote server controlled by the group," explains Koi Security's Tuval Admoni. "During initialization, they also transmit the victim’s external IP address, likely for tracking or targeting purposes." The crypto-draining operation is complemented by dozens of Russian-speaking pirated software websites that facilitate the distribution of 500 distinct malware executables, and also a network of websites impersonating Trezor, Jupiter Wallet, and fake wallet repair services. In the cases of malware, the payloads...

Read full article

Affected Software

4 affected components
Mozilla Firefox
MetaMask Extension
TronLink Extension
Rabby Extension
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a malicious campaign called 'GreedyBear' which has infiltrated the Firefox add-on store with 150 crypto-draining extensions.

2

What security implications are discussed?

The article highlights the risk of using compromised extensions that can steal cryptocurrency from users, leading to significant financial losses.

3

What products or software are affected?

The affected software includes Mozilla Firefox and several crypto wallet extensions such as MetaMask, TronLink, and Rabby.

4

How much money is estimated to have been stolen by these malicious extensions?

The estimated amount stolen from victims due to these extensions is around $1,000,000.

5

What should users do to protect themselves from such extensions?

Users should avoid downloading unfamiliar extensions and regularly audit their existing add-ons for any malicious activity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203