Loading market data...

Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets

Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets

... but the subtitle is not in the content. The original content has a lead paragraph. The subtitle is given as a separate field? The instructions say "ORIGINAL TITLE: should reflect the main news..." and then "ORIGINAL CONTENT:" includes the article. The subtitle is not in the content. So we don't need to include it. We'll just translate the content. We need to produce JSON with title, content, and meta description. The meta description we'll create in Finnish. Let's translate the content step by step. Original content:

. We'll produce JSON. Let's craft the article. Title: "Socket Finds 40 Malicious Firefox Add-ons Stealing Crypto Wallet Secrets" Slug: socket-finds-40-malicious-firefox-add-ons-stealing-crypto-wallet-secrets Subtitle: "The add-ons posed as sports-score tools and wallet apps; Mozilla signed some versions as early as March." Content: Lead: Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to siphon crypto wallet data. The campaign ran from at least March into August, with Mozilla signing 59 original versions between March 9 and Aug. 3, according to a report released Aug. 19. The affected add-ons targeted recovery phrases, private keys, and wallet keyrings, and anyone who installed them should consider their wallet compromised. Then sections. Section 1: "How the add-ons worked" - describe the four attack vectors. Section 2: "The sports-score disguise" - some add-ons had previously been legitimate sports-score tools, 37 were deceptive shells without confirmed theft. Section 3: "What users should do" - move assets, change passwords, etc. Section 4: "The open questions" - no confirmed victims or loss total. We'll write with human rhythm. Use contractions. Let's draft. We need to ensure no stale numbers. We have exact numbers from facts, that's fine. Now, we must produce JSON. We'll set wordCount to approximate. We'll compute later. Let's write the content. Lead: Security researchers at Socket have identified 40 Firefox add-ons with confirmed malicious behavior designed to steal crypto wallet data. The campaign ran from at least March into August, with Mozilla signing records showing 59 versions between March 9 and Aug. 3. The add-ons captured recovery phrases, private keys, and wallet keyrings — and anyone who used them should treat their wallet as compromised. Then H2: "How the add-ons worked" Then a paragraph: The 40 malicious identities split into four distinct attack paths. Seven were remote-controlled phishing loaders. Fifteen captured recovery phrases, private keys, or wallet secrets directly. Thirteen were modified clones of the Rabby wallet that sent serialized keyrings away before encryption. Five collected credentials and clipboard data. Each path ends with the same outcome: the attacker gets enough to drain a wallet. H2: "The sports-score disguise" - "Some of these add-ons had a previous life. Nine had distributed sports-score tools under the same IDs, and 37 more were deceptive or suspicious sports-score shells without a confirmed theft payload. That's a deliberate cover — a user might install a score app and later see a 'wallet helper' update." H2: "What users should do" - "Socket's advice is blunt: uninstalling the add-on can't revoke a secret that's already been exposed. Affected users should move any remaining assets to a fresh wallet created from a new recovery phrase, change passwords, terminate active sessions, and double-check any copied destination addresses before sending." H2: "What's still unknown" - "Socket documented the theft capability and exfiltration infrastructure but did not identify confirmed victims, attributable transactions, or a campaign loss total. The report also doesn't name the add-ons publicly, leaving users to wonder if they were caught. Mozilla says it uses automated risk indicators and human review to catch malicious wallet add-ons, and advises installing only extensions linked from the wallet provider's official site." End with a concrete next step: "Mozilla hasn't said whether it has pulled the specific add-ons or is still investigating. In the meantime, anyone who used a wallet-related Firefox extension this summer would be wise to treat it as hostile." We need to be careful: we said "didn't explain the add-ons publicly" - but facts don't say that. The facts say "Socket documented ... but did not identify confirmed victims..." It doesn't say whether add-ons are named. We shouldn't invent. We'll say "The report doesn't name confirmed victims or a total loss." That's fine. We also need to mention the 9 that previously distributed sports-score tools under the same IDs. That's in the first fact. We'll incorporate. We