A Rabby-focused subset included 13 impersonators that exfiltrated serialized wallet-keyring data before Rabby’s normal local encryption process. That gave the operators access to the data at a point when local encryption would not yet protect it.
The campaign’s 37 sports-score extensions were not confirmed as wallet stealers in the available analysis. Their connection to the malicious add-ons came from overlapping code, infrastructure, publishing patterns, and extension histories.
Socket’s reporting grouped the activity into four malicious clusters. The clusters shared technical and operational signals rather than relying on a single identical extension design, helping the operators distribute the campaign across multiple wallet brands and add-on identities.
The extensions also used services that made the operation easier to change and harder to inspect:
This combination meant that malicious behavior did not necessarily need to be embedded permanently in every published extension version. A remotely controlled phishing page could be switched on or off without submitting a new add-on update, reducing the chance that a review snapshot would capture the active behavior.
One of the campaign’s more important evasion signals was version repurposing. At least nine extensions began as sports-score applications and were later updated into wallet malware.
That approach can make an extension look less suspicious when first published: an add-on may establish a publishing history and accumulate user trust before a later version changes its behavior. In this case, Mozilla signing records, overlapping identities, common code, and shared infrastructure helped researchers connect apparently separate extensions to the same broader operation.
The signing records also indicate that activity reached back to at least March 2026. They support Socket’s assessment that the 77 identities represented a coordinated campaign rather than unrelated malicious submissions.
If you installed one of the suspicious extensions or entered sensitive information into it, respond as though that information is exposed:
A recovery phrase, private key, or imported wallet keyring should not be considered safe merely because no theft has appeared yet. The campaign was designed to collect data that could enable later account or asset access, so remediation should happen before suspicious activity is visible.
The campaign shows why marketplace presence and a valid browser-extension signature are not enough to establish trust. The linked add-ons combined fake Web3 branding, reused code, repurposed signed extensions, remote phishing switches, and shared infrastructure. Those signals became more meaningful when analyzed together than when each extension was examined in isolation.
The available evidence clearly supports the 77-extension campaign assessment and the Rabby keyring-exfiltration behavior. It does not, however, provide enough detail to reliably map every one of the four clusters to a specific extension family or identify the people behind the operation.