MetaMask / MetaMask/metamask-extension
Malicious Mozilla Metamask Extensions
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 13.2k
- Forks
- 5.6k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 451
Description
What is this about?
Someone is uploading malicious metamask extensions, that steals private keys on Mozilla official store.
they boost them by high fake reviews so they show up before the official extension in search results.
please make this stop, I lost lots of crypto due to this. I lowered my guard since this was the official store.
they recently made a fake profile with Danfinaly name and profile pic:
https://addons.mozilla.org/en-US/firefox/user/19061309
the previous extensions were removed but we could trace the server that receives the private key requests to
https://suirokboys.digital
the latest extension is
https://addons.mozilla.org/en-US/firefox/addon/metamask-crypto-wallet/
they encrypted the server this time.
example of previous profiles that created the extension that was taken out:
https://addons.mozilla.org/en-US/firefox/user/19053645/
if anyone can help track them down?
Scenario
No response
Design
No response
Technical Details
No response
Threat Modeling Framework
No response
Acceptance Criteria
No response
Stakeholder review needed before the work gets merged
- Engineering (needed in most cases)
- Design
- Product
- QA (automation tests are required to pass before merging PRs but not all changes are covered by automation tests - please review if QA is needed beyond automation tests)
- Security
- Legal
- Marketing
- Management (please specify)
- Other (please specify)
References
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The report names Mozilla Add-ons profiles, the listed extensions, and external URLs, but no repository file, test, or entry point. There is no defined repository change or acceptance criterion; a maintainer would need to establish scope before work can begin.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100