# Socket Weekly: 77 Firefox Wallet-Theft Extensions, Rust Crates Hit…

Canonical: https://brew.new/browse/templates/email/pt1_k97s6qt1gm6r9m5hnz2btb2xp98e4m7e

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: 77 Firefox Wallet-Theft Extensions, Rust Crates Hit…](https://cdn.brew.new/email-preview-a3d81997194b7fc3-tracking_r57j891f1b8ns9vnffqa4mdkp98dvj5y-1789060915909.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

77 Firefox Extensions Linked to Crypto Wallet and Credential Theft

Socket's research team linked 77 Firefox extensions in a single crypto-theft operation, 40 confirmed to steal wallet recovery phrases, private keys, and credentials while impersonating wallets like OKX, Rabby, and TronLink. Nine ran for months as benign sports-score tools before a routine update quietly converted them into wallet stealers. We're now scanning all 97k+ extensions listed in Mozilla's official addons.mozilla.org directory.

MORE NEWS

Popular Rust Crates Compromised in a Build-Time Supply Chain Attack

An attacker compromised three widely used Rust crates from the same maintainer, including arrayref, and added a dependency that runs malware during a normal Cargo build, before any of the crate's own code is called. It’s not just an npm problem anymore: this attack hit Rust crates with hundreds of millions of downloads.

Open VSX Unblocks Extension IDs That Were Used in a Malware Campaign

After Open VSX blocked 77 malicious extensions and published their IDs, it unblocked a few so legitimate maintainers could reclaim the names. That breaks any blocklist keyed on extension ID alone, because the old malware and the now-approved package resolve under the same identifier, and it points to a wider namespace gap where our team found hundreds of Open VSX IDs impersonating popular VS Code extensions.

MORE WORTH READING

GitHub: Block users directly from security advisories

Pacing model development in an era of cyber-critical capabilities

Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime

The August 17 outage, and the work ahead

Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97s6qt1gm6r9m5hnz2btb2xp98e4m7e)

[Browse email designs](https://brew.new/browse/templates)
