Malicious Firefox extensions are targeting cryptocurrency users by impersonating popular wallets such as Rabby and OKX, stealing recovery phrases and private keys entered during wallet import flows.
Security researchers at Socket identified 16 malicious Mozilla Firefox extensions linked to the campaign. Four were repackaged clones of Rabby Wallet, while twelve used interfaces closely resembling OKX Wallet.
The malicious add-ons were designed to capture 12-word or 24-word recovery phrases and, in some variants, raw private keys before sending the secrets to attacker-controlled Cloudflare Workers infrastructure.
Mozilla had unpublished the identified extensions by October 5, 2026, according to Socket. However, users who entered genuine wallet secrets into any functioning variant should assume those credentials are permanently compromised.
For broader protection against credential theft, malicious software and account compromise, see our Consumer and Small Business Cybersecurity Defense Hub.
Key takeaway: Removing the malicious extension is not enough if a recovery phrase or private key was already exposed. Affected users should create a new wallet from a clean device and transfer their assets immediately.
What Did the Malicious Firefox Extensions Do?
The campaign used browser extensions that appeared to be legitimate cryptocurrency wallet tools or ordinary browser utilities.
Behind the familiar-looking interfaces, malicious code intercepted wallet recovery phrases and private keys as victims imported existing wallets.
Socket researchers found that the extensions were built around two main families:
- Four large extensions cloned Rabby Wallet.
- Twelve smaller extensions mimicked OKX-style wallet interfaces.
The attackers changed extension names, versions, IDs, descriptions and visual presentation while reusing the same credential-stealing logic and infrastructure.
Rabby Wallet Clones Captured Seed Phrases and Private Keys
The four Rabby-style extensions were not simple phishing forms.
They contained large repackaged wallet applications with more than one thousand files and substantial portions of Rabby’s legitimate interface and functionality.
The fake branding used the misspelled name “Raabby WaIIet”, while parts of the package still referenced legitimate Rabby and DeBank services.
This made the extensions appear more convincing because much of the underlying interface behaved like a real cryptocurrency wallet.
Researchers found malicious hooks inserted into legitimate-looking wallet import operations.
These hooks captured:
- 12-word recovery phrases
- 24-word recovery phrases
- 64-character hexadecimal private keys
The stolen data was then transmitted to attacker-controlled infrastructure.
OKX Wallet Clones Used Fake Import Screens
The second group consisted of twelve smaller Firefox extensions using interfaces that closely resembled OKX Wallet.
The fake wallet portal asked users to enter a 12-word or 24-word recovery phrase.
Once the phrase passed the extension’s validation checks, it was forwarded to a background script responsible for sending the wallet secret to remote infrastructure.
Eleven of the twelve OKX-style variants were capable of performing this flow as packaged.
One extension, identified as sipoo-grozza@browserweb.com, contained the credential-theft code but was broken because its manifest failed to load the required background script and used mismatched message handlers.
Socket emphasized that the broken implementation did not indicate benign intent because the package still contained explicit credential collection and exfiltration logic.
How Were Wallet Secrets Exfiltrated?
The extensions used attacker-controlled Cloudflare Workers endpoints to receive stolen wallet information.
Fifteen of the sixteen extensions contacted infrastructure under the domain:
icy-star-f45c[.]workers[.]dev
The broken variant used a different Workers domain but retained similar frontend and campaign markers.
The Rabby clones transmitted secrets through HTTP GET requests containing the recovery phrase or private key directly in URL parameters.
This method created additional exposure because URLs can be recorded in server logs and intermediary network logs.
The OKX-style variants primarily used HTTPS POST requests containing the raw recovery phrase.
Extension Permissions Claimed No Data Collection
One particularly important finding was that every extension manifest declared Firefox data collection permission as none.
That claim directly contradicted the underlying code, which actively processed and transmitted cryptocurrency wallet recovery material.
This demonstrates why permission declarations alone should not be treated as proof that a browser extension is safe.
Why Recovery Phrase Theft Is So Dangerous
A cryptocurrency recovery phrase is effectively a master key to a wallet.
Anyone who obtains it can generally recreate the wallet on another device and gain control of the associated assets.
This differs from an ordinary website password.
Changing a browser extension password does not invalidate a stolen recovery phrase or private key.
Once that secret has been exposed, the safest response is to move funds to an entirely new wallet created with a new recovery phrase.
Full List of the 16 Malicious Extensions
Socket identified the following extension packages in the campaign:
view-focus-bright@webtools.co— version 6.12.2quick-track-nest@tabtools.co— version 8.1.18vibe-kit-tool@fasttools.co— version 9.21.9edge-hub-snap@protools.net— version 4.12.24core-hub-peak@neattools.example— version 8.24.21sipoo-grozza@browserweb.com— version 2.1mozart-seo@webtools.com— version 1.4clean-file-bar@neattools.com— version 4.21.8clean-net-timer@plugify.example— version 4.17.1manager-square@webtools.com— version 1.4manager-course@webtools.com— version 1.4val-andrew@browserweb.com— version 1.4manager-team@browserweb.com— version 1.4valory-andrew@browserweb.com— version 1.4franklin-uk@browserweb.com— version 1.4franklin-uro@browserweb.com— version 1.4
Mozilla had removed the extensions by October 5, 2026, but users should still review synchronized Firefox profiles and other devices where the extensions may previously have been installed.
The Campaign Appears to Be an Earlier Threat Wave Continuing
Socket assesses with high confidence that the operation is connected to an earlier cryptocurrency wallet extension campaign documented in August 2026.
The assessment is based on reused infrastructure, code patterns, campaign markers, wallet interfaces and exfiltration logic.
The operators appear to rotate visible characteristics such as extension IDs and package names while keeping the underlying credential-stealing architecture largely unchanged.
This type of rotation can make simple blocklists less effective because defenders may focus on individual extension names rather than shared behavior and infrastructure.
Why Fake Wallet Extensions Are Effective
Cryptocurrency wallet extensions are attractive phishing targets because users expect them to request highly sensitive information during legitimate wallet recovery.
A recovery phrase request that would appear suspicious on a normal website can seem completely normal inside a wallet import screen.
Attackers can exploit that expectation by cloning trusted wallet interfaces and adding malicious collection logic behind them.
The Rabby clones in this campaign went further by preserving large amounts of legitimate wallet functionality and branding, making the deception harder to spot.
How to Check Whether You Were Affected
Firefox users should review installed extensions and compare them against the identified extension IDs.
Also check other devices using the same synchronized Firefox profile.
If one of the malicious extensions was installed but no real recovery phrase or private key was entered, exposure may be more limited.
If a real wallet secret was entered, the wallet should be treated as compromised even if no unauthorized transaction has appeared yet.
What Affected Crypto Users Should Do Immediately
Socket recommends that affected users take the following steps:
- Remove the identified malicious extension from Firefox.
- Stop using the affected wallet environment.
- Use a clean device to create a completely new wallet.
- Generate a new recovery phrase.
- Transfer cryptocurrency and other assets to the new wallet.
- Revoke token approvals associated with the exposed wallet where appropriate.
- Assume all accounts derived from the compromised mnemonic are exposed.
- Review synchronized Firefox profiles on other devices.
Simply changing the extension password is not sufficient because the underlying wallet recovery secret may already be in the attacker’s possession.
How to Reduce the Risk of Malicious Browser Extensions
Users should avoid installing cryptocurrency wallet extensions based only on a familiar logo or similar product name.
Safer practices include:
- Install wallet extensions only from links provided by the vendor’s official website.
- Verify the publisher and extension ID before installation.
- Review requested permissions carefully.
- Remove browser extensions that are no longer needed.
- Use separate browser profiles for cryptocurrency activity where practical.
- Never enter a recovery phrase into an unexpected extension or website.
- Keep recovery phrases offline whenever possible.
- Use hardware wallets for higher-value cryptocurrency holdings where appropriate.
Why Extension Stores Cannot Be the Only Trust Signal
Official browser extension marketplaces reduce some risk, but they cannot guarantee that every published add-on is safe.
Malicious developers frequently change identifiers, descriptions, assets and package versions in an attempt to bypass review systems.
This campaign shows that attackers can also reuse legitimate application code while inserting only a small number of malicious credential-stealing hooks.
That makes some fake extensions significantly more convincing than basic phishing copies.
Organizations Should Audit Browser Extensions Too
The risk is not limited to individual cryptocurrency users.
Organizations that allow unmanaged browser extensions can expose employees to credential theft, session theft and other forms of browser-based compromise.
Security teams should maintain extension inventories and consider restricting installation to approved add-ons in managed environments.
Behavior-based monitoring can also help detect extensions that communicate with unexpected external destinations or access data beyond their stated purpose.
Frequently Asked Questions
What are the malicious Firefox extensions?
They are a group of 16 Firefox extensions identified by Socket that impersonated cryptocurrency wallets or browser utilities while stealing recovery phrases and private keys.
Which wallets were impersonated?
Researchers found four Rabby Wallet clones and twelve extensions using interfaces derived from or closely resembling OKX Wallet.
What information did the extensions steal?
Depending on the variant, they targeted 12-word and 24-word recovery phrases as well as raw private keys.
Were the extensions removed?
Yes. Socket reported that Mozilla had unpublished the identified extensions by October 5, 2026.
Is removing the malicious extension enough?
No, not if a real recovery phrase or private key was entered. The wallet should be treated as compromised and assets should be moved to a newly created wallet.
Can changing the wallet password protect the funds?
No. A stolen recovery phrase or private key can still be used to recreate or access the wallet independently of the extension password.
Were all 16 extensions fully functional?
No. One OKX-style variant contained malicious collection and exfiltration code but was broken because its packaged configuration did not correctly load the background script.
Where were the stolen secrets sent?
Most variants attempted to send the information to attacker-controlled Cloudflare Workers infrastructure.
Final Takeaway
The discovery of 16 malicious Firefox extensions shows how convincing cryptocurrency wallet impersonation can become when attackers reuse legitimate interfaces and inject credential-stealing code into familiar workflows.
The most serious risk is not simply the presence of the extension itself, but exposure of the wallet’s recovery phrase or private key.
Users who entered genuine secrets into one of the identified extensions should create a new wallet from a trusted environment and move their assets rather than relying on a password change or extension removal.
Stay Updated on Browser and Crypto Security
Malicious browser extensions continue to evolve from simple adware into sophisticated tools for credential theft, session hijacking and cryptocurrency theft.
Follow CyberUpdates365 for verified cybersecurity news, malware research, phishing alerts, browser security threats and practical protection guidance.
Primary Source
Socket Threat Research:
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials




