Loading market data...

Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets

Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets

. We have a title and subtitle in the instructions? The original content is given as a full article with h2 sections. The subtitle is not explicitly in the content; it's part of the instructions. We need to include the subtitle in the content? The original content has a lead paragraph. The subtitle is not in the HTML. We'll just translate the content as given. The content includes the lead and sections. We'll translate that. We need to produce the content in HTML. We'll translate each paragraph. Let's translate the lead: "Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to steal crypto wallet data. The campaign ran from at least March into August, with Mozilla signing records showing 59 versions between March 9 and Aug. 3, and activity clustering in April and late July. Anyone whose recovery phrase, private key, or wallet keyring was exposed to a malicious version must treat the wallet as compromised — uninstalling the add-on can't revoke a secret that's already been sent." Translation: "সকেটের নিরাপত্তা গবেষকরা ৪০টি ফায়ারফক্স অ্যাড-অন শনাক্ত করেছেন যেগুলোর নিশ্চিত ক্ষতিকারক আচরণ ক্রিপ্টো ওয়ালেটের তথ্য চুরি করার জন্য ডিজাইন করা হয়েছে। এই প্রচারণা অন্তত মার্চ থেকে আগস্ট পর্যন্ত চলেছে, মোজিলার স্বাক্ষরিত রেকর্ড অনুযায়ী ৯ মার্চ থেকে ৩ আগস্টের মধ্যে ৫৯টি সংস্করণ ছিল এবং এপ্রিল ও জুলাইয়ের শেষে কার্যকলাপ ঘনীভূত ছিল। যাদের রিকভারি ফ্রেজ, প্রাইভেট কী বা ওয়ালেট কিরিং একটি ক্ষতিকারক সংস্করণের সংস্পর্শে এসেছে, তাদের অবশ্যই ওয়ালেটটি আপস করা হয়েছে বলে ধরে নিতে হবে — অ্যাড-অন আনইনস্টল করলে ইতিমধ্যে পাঠানো গোপন তথ্য ফিরিয়ে আনা যাবে না।" We need to keep "Socket" as is, "Firefox" as is, "Mozilla" as is. "recovery phrase" -> "রিকভারি ফ্রেজ" or "পুনরুদ্ধার বাক্যাংশ"? We'll use "রিকভারি ফ্রেজ" as it's common. "private key" -> "প্রাইভেট কী". "wallet keyring" -> "ওয়ালেট কিরিং" (we'll keep as is). "compromised" -> "আপস" or "ঝুঁকিপূর্ণ"? We'll use "আপস" as it's common in tech. Now section 1: "How the add-ons worked" -> "অ্যাড-অনগুলো কীভাবে কাজ করেছিল" Paragraph: "The 40 malicious identities used four distinct attack paths. Seven were remote-controlled phishing loaders. Fifteen captured recovery phrases, private keys, or wallet secrets. Thirteen were modified clones of the Rabby wallet that sent serialized keyrings away before encryption. And five collected credentials and clipboard data. Each path ends with the same outcome: the attacker can empty the wallet." Translation: "৪০টি ক্ষতিকারক পরিচয় চারটি ভিন্ন আক্রমণের পথ ব্যবহার করেছে। সাতটি ছিল রিমোট-নিয়ন্ত্রিত ফিশিং লোডার। পনেরোটি রিকভারি ফ্রেজ, প্রাইভেট কী বা ওয়ালেটের গোপন তথ্য ক্যাপচার করেছে। তেরোটি ছিল র্যাবি ওয়ালেটের পরিবর্তিত ক্লোন যা এনক্রিপশনের আগে সিরিয়ালাইজড কিরিং পাঠিয়ে দেয়। এবং পাঁচটি ক্রেডেনশিয়াল এবং ক্লিপবোর্ড ডেটা সংগ্রহ করেছে। প্রতিটি পথ একই ফলাফলে শেষ হয়: আক্রমণকারী ওয়ালেট খালি করতে পারে।" We need to keep "Rabby" as is. "serialized keyrings" -> "সিরিয়ালাইজড কিরিং" or "সিরিয়ালাইজড কী-রিং"? We'll use "সিরিয়ালাইজড কিরিং" as it's a technical term. Section 2: "The sports-score disguise" -> "স্পোর্টস-স্কোর ছদ্মবেশ" Paragraph: "Some of these add-ons had a double life. Nine of them had previously distributed sports-score tools under the same IDs, and the report lists 37 more as deceptive or suspicious sports-score shells without a confirmed theft payload. That's a plausible cover: a user installs a score app, then a 'wallet' update appears later." Translation: "এই অ্যাড-অনগুলোর কিছু ছিল দ্বৈত জীবন। এর মধ্যে নয়টি আগে একই আইডিতে স্পোর্টস-স্কোর টুল বিতরণ করেছিল, এবং প্রতিবেদনে আরও ৩৭টি প্রতারণামূলক বা সন্দেহজনক স্পোর্টস-স্কোর শেল হিসেবে তালিকাভুক্ত করা হয়েছে যাদের নিশ্চিত চুরির পেলোড নেই। এটি একটি যুক্তিযুক্ত কভার: একজন ব্যবহারকারী একটি স্কোর অ্যাপ ইনস্টল করে, তারপর পরে একটি 'ওয়ালেট' আপডেট আসে।" Section 3: "What users should do" -> "ব্যবহারকারীদের কী করা উচিত" Paragraph: "Socket's advice is blunt: uninstalling the add-on doesn't fix anything. Affected users should move remaining assets to a fresh crypto wallet created from a new recovery phrase, change passwords, terminate active sessions, and verify any copied destination addresses before sending. The threat isn't limited to the wallet itself — any credential or session that touched the add-on is suspect." Translation: "সকেটের পরামর্শ স্পষ্ট: অ্যাড-অন আনইনস্টল করলে কিছুই ঠিক হয় না। আক্রান্ত ব্যবহারকারীদের অবশিষ্ট সম্পদ একটি নতুন রিকভারি ফ্রেজ থেকে তৈরি করা নতুন ক্রিপ্টো ওয়ালেটে সরানো উচিত, পাসওয়ার্ড পরিবর্তন করা উচিত, সক্রিয় সেশন শেষ করা উচিত এবং পাঠানোর আগে কপি করা গন্তব্য ঠিকানা যাচাই করা উচিত। হুমকি শুধু ওয়ালেটের মধ্যে সীমাবদ্ধ নয় — অ্যাড-অনের সংস্পর্শে আসা যেকোনো ক্রেডেনশিয়াল বা সেশন সন্দেহজনক।" Section 4: "What's still unknown" -> "এখনও কী অজানা" Paragraph: "Socket documented the theft capability and exfiltration infrastructure but didn't identify confirmed victims, attributable transactions, or a campaign loss total. Mozilla says it uses automated risk indicators and human review to catch malicious wallet add-ons, and advises