Morning Edition · Wednesday, August 26, 2026Published at 1:49 AM EDT · New York
Socket linked 77 extension identities to one campaign running since March, with theft code arriving in later updates that browser review had already approved.

Socket Threat Research linked 77 Firefox extension identities through shared code and infrastructure and confirmed 40 of them as malicious, in a campaign it says has run since at least March. The confirmed add-ons impersonate the wallets OK…
Track on-chain flows, protocol shifts, stablecoins, and regulation.
The Global Intelligence Brief stays free.
Part of a tracked trend
Wallet Theft Moves to the Distribution Layer
Attackers keep shifting from protocol code to the software supply chain that reaches users, including extension stores, update channels and device firmware, so losses increasingly originate in components that passed review before the malicious payload existed.
Start a discussion in Townsquare.
More from this edition
Comments
0No comments yet.