Loading market data...

should reflect the main news: that a security firm found these add-ons. Use

should reflect the main news: that a security firm found these add-ons. Use

. We'll produce JSON. Let's craft the article. Title: "Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets" Slug: socket-finds-40-malicious-firefox-add-ons-stealing-crypto-wallet-secrets Subtitle: "The add-ons posed as sports-score tools and wallet apps; Mozilla signed some versions as early as March." Content: Lead: Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to siphon crypto wallet data. The campaign ran from at least March into August, with Mozilla signing 59 original versions between March 9 and Aug. 3, according to a report released Aug. 19. The affected add-ons targeted recovery phrases, private keys, and wallet keyrings, and anyone who installed them should consider their wallet compromised. Then sections. Section 1: "How the add-ons worked" - describe the four attack vectors. Section 2: "The sports-score disguise" - some add-ons had previously been legitimate sports-score tools, 37 were deceptive shells without confirmed theft. Section 3: "What users should do" - move assets, change passwords, etc. Section 4: "The open questions" - no confirmed victims or loss total. We'll write with human rhythm. Use contractions. Let's draft. We need to ensure no stale numbers. We have exact numbers from facts, that's fine. Now, we must produce JSON. We'll set wordCount to approximate. We'll compute later. Let's write the content. Lead: Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to steal crypto wallet data. The campaign ran from at least March into August, with Mozilla signing records showing 59 versions between March 9 and Aug. 3. The add-ons captured recovery phrases, private keys, and wallet keyrings — and anyone who used them should treat their wallet as compromised. Then H2: "How the add-ons worked" Then a paragraph: The 40 malicious identities split into four distinct attack paths. Seven were remote-controlled phishing loaders. Fifteen captured recovery phrases, private keys, or wallet secrets directly. Thirteen were modified clones of the Rabby wallet that sent serialized keyrings away before encryption. Five collected credentials and clipboard data. Each path ends with the same outcome: the attacker gets enough to drain a wallet. H2: "The sports-score disguise" - "Some of these add-ons had a previous life. Nine had distributed sports-score tools under the same IDs, and 37 more were deceptive or suspicious sports-score shells without a confirmed theft payload. That's a deliberate cover — a user might install a score app and later see a 'wallet helper' update." H2: "What users should do" - "Socket's advice is blunt: uninstalling the add-on can't revoke a secret that's already been exposed. Affected users should move any remaining assets to a fresh wallet created from a new recovery phrase, change passwords, terminate active sessions, and double-check any copied destination addresses before sending." H2: "What's still unknown" - "Socket documented the theft capability and exfiltration infrastructure but did not identify confirmed victims, attributable transactions, or a campaign loss total. The report also doesn't name the add-ons publicly, leaving users to wonder if they were caught. Mozilla says it uses automated risk indicators and human review to catch malicious wallet add-ons, and advises installing only extensions linked from the wallet provider's official site." End with a concrete next step: "Mozilla hasn't said whether it has pulled the specific add-ons or is still investigating. In the meantime, anyone who used a wallet-related Firefox extension this summer would be wise to treat it as hostile." We need to be careful: we said "didn't explain the add-ons publicly" - but facts don't say that. The facts say "Socket documented ... but did not identify confirmed victims..." It doesn't say whether add-ons are named. We shouldn't invent. We'll say "The report doesn't name confirmed victims or a total loss." That's fine. We also need to mention the 9 that previously distributed sports-score tools under the same IDs. That's in the first fact. We'll incorporate. We need to make sure we don't use "industry experts" etc. We have no quotes. Let's write the article in HTML. I'll count words approximately. We'll target ~600. Let me write. I'll produce the JSON. Meta description: "Socket found 40 Firefox add-ons with malicious behavior targeting crypto wallets. Learn the attack vectors and what to do if you're affected." That's about 150 chars. Let's count. "Socket found 40 Firefox add-ons with malicious behavior targeting crypto wallets. Learn the attack vectors and what to do if you're affected." - count: I'll trust. Focus keyword: "malicious Firefox add-ons crypto wallet" Keywords: ["Firefox add-ons", "crypto wallet theft", "Socket research", "Mozilla security", "wallet recovery phrase"] Now, we need to ensure the article is not too long. We'll write and then count. Let's draft the content string. I'll write:

Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to steal crypto wallet data. The add-ons ran from at least March into August, with Mozilla signing records showing 59 versions between March 9 and Aug. 3. Anyone whose recovery phrase, private key, or wallet keyring was exposed to a malicious version must treat the wallet as compromised — uninstalling the add-on can't revoke a secret that's already been sent.

Then h2: How the add-ons worked

The 40 malicious identities used distinct attack paths. Seven were remote-controlled phishing loaders. Fifteen captured recovery phrases, private keys, or wallet secrets. Thirteen were modified clones of the Rabby wallet that sent serialized keyrings away before encryption. And five collected credentials and clipboard data. Each path ends the same way: the attacker gains enough to empty the wallet.

The sports-score disguise

Some of these add-ons had a prior life. Nine of them had previously distributed sports-score tools under the same IDs, and the report lists 37 more as deceptive or suspicious sports-score shells without a confirmed theft payload. That's a plausible cover: a user installs a score app, then a "wallet update" appears later.

What users should do

Socket's advice is blunt: uninstalling the add-on doesn't fix anything. Affected users should move remaining assets to a fresh crypto wallet created from a new recovery phrase, change passwords, terminate active sessions, and verify any copied destination addresses before sending. The threat isn't limited to the add-on itself — any session or credential it touched is suspect.

What's still unknown

Socket documented the theft capability and exfiltration infrastructure but didn't identify confirmed victims, attributable transactions, or a campaign loss total. Mozilla uses automated risk indicators and human review to catch malicious wallet add-ons, and advises users to install only extensions linked from the wallet provider's official site. Whether Mozilla has already pulled these specific add-ons or is still investigating hasn't been disclosed.

For now, the safest move for anyone who used a Firefox wallet extension in the past few months is to treat it as compromised and start fresh.

That last paragraph is a closing. We can make it the ending. But we need to avoid "" etc. That's fine. We need to ensure the lead is 2-3 sentences. We have three. Good. Now, we need to make sure we don't have any stale numbers. We used the numbers from facts. Now, we need to count words. Let me count the paragraphs. I'll write in a text file mentally. Lead: ~60 words. Section 1: ~80. Section 2: ~60. Section 3: ~80. Section 4: ~100. Last paragraph: ~30. Total ~410. We need 450-700. So we can expand a bit. We can add more detail. For example, mention the campaign activity clustering in April and late July. Also mention that 40 are confirmed malicious, 37 deceptive. We have that. We can add a sentence about the report's scope. Also mention that Mozilla signs versions. We already have. We can expand the "What users should do" section with more specific steps: change passwords, terminate active sessions, verify copied addresses. We have that. We can expand the "What's still unknown" with the fact that Socket documented but didn't identify victims. We have that. We can also add a sentence about the timing: activity clustered in April and late July. That could go in the lead or the first section. Let's add: "Activity clustered in April and again in late July, according to the report." We'll put that in the lead or the first section. Let's rewrite the lead: "Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to steal crypto wallet data. The campaign ran from at least March into August, with Mozilla signing records showing 59 versions between March 9 and Aug. 3, and activity clustering in April and late July. Anyone whose recovery phrase, private key, or wallet keyring was exposed to a malicious version must treat the wallet as compromised — uninstalling the add-on can't revoke a secret that's already been sent." That's a bit longer. Good. Now, we can expand the "How the add-ons worked" with a bit more detail: "The attack paths ranged from simple phishing loaders to clones of Rabby wallet." That's already. We can add a sentence about the 37 deceptive ones in that section. Let me restructure: Lead: 3 sentences. Section 1: How the add-ons worked - mention the four types. Section 2: The sports-score disguise - mention that some had previous sports tools, 37 deceptive. Section 3: What users should do - steps. Section 4: What's still unknown - about victims and Mozilla. Closing sentence. Now, we'll write in HTML. I'll write the content string. We also need to ensure we use proper HTML entities. Now, let's produce the JSON. I'll write the title as "Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets" - but that might be long. Alternatively "Socket Uncovers 40 Malicious Firefox Add-ons That Steal Crypto Wallet Secrets" - but we can go with "Socket Uncovers 40 Malicious Firefox Add-ons Targeting Crypto Wallets" - but that's generic. Since we know they steal, we can say "Socket Finds 40 Firefox Add-ons Stealing Crypto Wallet Keys" - but we don't know keys? Yes, recovery phrases, private keys, keyrings. So "Wallet Secrets" is good. Let's settle: "Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets" Subtitle: "The add-ons ran from March to August; some were disguised as sports-score tools." Description: "A new report identifies 40 Firefox add-ons that steal crypto wallet recovery phrases, private keys, and keyrings. Here's what to do if you've installed one." Focus keyword: "malicious Firefox add-ons crypto wallet" Keywords: ["Firefox add-ons", "crypto wallet theft", "Socket research", "Rabby wallet clone", "sports-score add-ons"] Now, we need to ensure we don't have any AI tics. We have "That's a plausible cover" which is a dry observation, good. We need to ensure we don't have "Furthermore" etc. Now, we'll produce the JSON. One more thing: We have "The report doesn't identify confirmed victims" - that's fine. We need to make sure the word count is within range. We'll count. Let me write the content string: "

Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to steal crypto wallet data. The campaign ran from at least March into August, with Mozilla signed versions between March 9 and Aug. 3, and activity clustering in April and late July. Anyone whose recovery phrase, private key, or wallet keyring was exposed to a malicious version must treat the wallet as compromised — uninstalling the add-on can't revoke a secret that's already been sent.

How the add-ons worked

The 40 malicious identities used four distinct attack paths. Seven were remote-controlled phishing loaders. Fifteen captured recovery phrases, private keys, or wallet secrets. Thirteen were modified clones of the Rabby wallet that sent serialized keyrings away before encryption. And five collected credentials and clipboard data. Each path ends with the same outcome: the attacker can empty the wallet.

The sports-score disguise

Some of these add-ons had a double life. Nine of them had previously distributed sports-score tools under the same IDs, and the report lists 37 more as deceptive or suspicious sports-score shells without a confirmed theft payload. That's a plausible cover: a user installs a score app, then a 'wallet' update appears later.

What users should do

Socket's advice is blunt: uninstalling the add-on doesn't fix anything. Affected users should move remaining assets to a fresh crypto wallet created from a new recovery phrase, change passwords, terminate active sessions, and verify any copied destination addresses before sending. The threat isn't limited to the wallet itself — any credential or session that touched the add-on is suspect.

What's still unknown

Socket documented the theft capability and exfiltration infrastructure but didn't identify confirmed victims, attributable transactions, or a campaign loss total. Mozilla says it uses automated risk indicators and human review to catch malicious wallet add-ons, and advises users to install only extensions linked from the wallet provider's official site. It hasn't said whether these specific add-ons have been pulled or if a wider cleanup is in