Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root
October 9, 2026
GhostAction Attack Steals Secrets from GitHub Repositories
October 9, 2026
Critical Vulnerability in Terraform Exposes Developer Systems to Malware
October 9, 2026
Home/Threats/Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases
Threats

Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases

Key Takeaways A total of 16 malicious Firefox extensions impersonated legitimate cryptocurrency wallets to steal recovery phrases and private keys. The compromised extensions mimicked Rabby Wallet...

Emy Elsamnoudy
Emy Elsamnoudy
October 8, 2026 5 Min Read
15 0

Key Takeaways

  • A total of 16 malicious Firefox extensions impersonated legitimate cryptocurrency wallets to steal recovery phrases and private keys.
  • The compromised extensions mimicked Rabby Wallet and OKX Wallet interfaces, tricking users into revealing sensitive information during wallet import.
  • Mozilla removed the fraudulent add-ons from its marketplace by October 5, 2026, but users who have already entered credentials remain at risk.
  • The stolen data was exfiltrated to attacker-controlled Cloudflare Workers via both GET and POST requests.
  • Users who interacted with these extensions should immediately secure their assets and revoke token approvals.

A recent surge in malicious activity has seen cybercriminals deploy 16 counterfeit Firefox extensions designed to pilfer cryptocurrency recovery phrases and private keys from unsuspecting users. These add-ons, masquerading as legitimate wallet portals, desktop tools, and browser utilities, secretly transmitted sensitive user data to attacker-controlled Cloudflare Workers.

Table Of Content

  • Key Takeaways
  • Deceptive Wallet Interfaces and Malicious Code
  • Exfiltration Via Cloudflare Workers
  • Network and Code Indicators
  • Shared File Hashes
  • Extension IDs and Package Hashes
  • What You Should Do

The campaign specifically targeted users of Rabby Wallet and OKX Wallet, meticulously replicating their interfaces to transform standard wallet import processes into sophisticated traps. While Mozilla acted swiftly to remove these malicious extensions from its official marketplace by October 5, 2026, the removal does not mitigate the risk for individuals who previously entered their recovery phrases or private keys into an active fraudulent extension. Researchers from Socket.dev identified this threat and released their findings on October 7, detailing the operational tactics of the attackers.

Socket.dev’s investigation uncovered four extensive clones of Rabby Wallet and twelve smaller extensions styled after OKX Wallet. Among the smaller packages, eleven contained active background scripts engineered for credential theft, while one included similar theft code that was not executed through its standard packaging workflow. The researchers confidently linked this activity to a prior August campaign, citing shared codebases, infrastructure, and a consistent tracking marker. This continuity highlights a persistent strategy by attackers to re-deploy related malicious packages under new guises, continuously leveraging fake wallet interfaces and Cloudflare Workers for data exfiltration.

Deceptive Wallet Interfaces and Malicious Code

Each of the Rabby Wallet clones was remarkably complex, comprising 1,114 files. These files included fully functional-looking wallet import screens, account management modules, and transaction interfaces. Rather than employing rudimentary phishing pages, the attackers developed comprehensive wallet applications, integrating their theft functionalities seamlessly. To enhance credibility, some official Rabby links and DeBank service configurations were retained within the altered software.

Despite the sophisticated mimicry, inconsistencies in branding were present; for instance, the welcome screen correctly displayed “Rabby Wallet,” while other sections used a misspelled variation. Crucially, the malicious functions were strategically positioned to activate immediately following private-key and recovery-phrase import operations. These functions were designed to accept both 12-word or 24-word recovery phrases and 64-character hexadecimal private keys, capturing the exact secrets processed by the purported wallet. This method exploits user trust in familiar interfaces, rather than relying on vulnerabilities in genuine wallet services. The copied application could even continue its normal wallet operations while the theft code ran in the background, making detection difficult for the user.

The smaller extensions, which presented an OKX-derived interface under generic portal branding, also featured an import form that validated input for exactly 12 or 24 words before transmitting the phrase to a background handler. This handler was programmed to clean input by removing surrounding spaces, rejecting empty entries, and preventing the submission of duplicate phrases during a single session.

Exfiltration Via Cloudflare Workers

The Rabby Wallet clones exfiltrated stolen secrets embedded within GET request URLs, with a secondary request method available as a fallback. This method not only exposed recovery material to the attacker’s designated endpoint but also to any intermediate systems that log request URLs. In contrast, the active OKX-style handlers transmitted raw phrases securely via HTTPS POST requests containing JSON data.

One particular packaged background script offered three different transmission methods: a browser beacon, a POST request, and an image-based GET fallback. Although its internal comments falsely claimed that only a hash and word count were sent from the device, Socket.dev’s analysis confirmed that the full phrase was transmitted, with the hash serving merely to prevent duplicate submissions. A “broken” extension within the campaign lacked the necessary manifest entry to load its background script, and its interface sent messages that the handler was not configured to accept, limiting its operational capacity despite clear malicious intent. This echoes similar TronLink wallet impersonation attacks, which also leveraged copied wallet interfaces as credential traps, though with distinct delivery and collection mechanisms.

All identified extensions falsely declared that they collected no user data, directly contradicting their embedded secret-handling code. The Rabby clones further requested extensive browser access. However, Socket.dev’s static analysis did not conclusively identify a broader form-grabbing capability, confirming the primary objective as wallet-secret theft rather than comprehensive browsing data collection.

It is important to note that legitimate Rabby and DeBank domains found within the packages are not indicators of compromise themselves. Any individual who entered a legitimate recovery phrase or private key into a functional variant of these malicious extensions should consider their wallet irrevocably compromised. Socket.dev advises immediate action: remove the compromised extensions, establish a new wallet on a clean device, transfer all assets, and revoke any relevant token approvals. Simply changing the extension password will not invalidate a previously stolen recovery phrase or private key.

Defenders should meticulously audit their extension inventories, browser profiles, synchronized add-ons, and network logs against the provided indicators of compromise. Searches should prioritize matching destination hosts, request patterns, hashes, and campaign markers, ensuring that stolen phrases are redacted from alerts or case notes. Suspicious packages should be preserved for further investigation but must never be executed on an analyst’s primary workstation.

Indicators of Compromise (IoCs):-

Network and Code Indicators

Type Indicator Purpose
Network endpoint hxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/ Rabby-clone secret collection
Network endpoint hxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/ OKX-style secret collection
Network endpoint hxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/ OKX-style secret collection
Network endpoint hxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/ Endpoint packaged in the broken variant
Campaign marker EQOx7EIPZSNi Shared campaign token
Fake branding Raabby WaIIet Rabby-clone detection string
Runtime message SEED_PHRASE_IMPORT Recovery-phrase submission
Runtime message WALLET_SYNC Legacy message handled by theft code

Shared File Hashes

File or Component SHA-256
Rabby-clone background.js 7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799
OKX core background.js da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd
Broken variant background.js be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897
OKX Web3 Portal background.js c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f
Shared compact frontend eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf

Extension IDs and Package Hashes

Firefox Extension ID Version XPI SHA-256
[email protected] 6.12.2 2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51
[email protected] 8.1.18 225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b
[email protected] 9.21.9 6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8
[email protected] 4.12.24 8906dd85b0991fac14e5973b3f3f61d93ef1101504cb5867a004c762ee184ef7
[email protected] 8.24.21 9fea0ee3c81047f5e50eeb3a2ab2a7cd70357f3e49944b7079ab3e90c9ea0e8b
[email protected] 2.1 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35
[email protected] 1.4 635b31b4a19b5673fcbe0fedeb3f7ed2c27fddb739685f19ca5f3d1f1d7f0083
[email protected] 4.21.8 d9432e41e0401715bce4ce11f4a7104d94fab1ec89be553ba57a2097e418c1a1
[email protected] 4.17.1 458e7255438f15aaede02fd7f8fcfdf762aa6e08608b9546fe8aa8aa399c76b7
[email protected] 1.4 bb8f60b3f77d96adc93bf0515b34df7c5f1f560a9f6d0c353b7d849609e3557d
[email protected] 1.4 71ec70479ab78efb1e1f9507f8ff7348d5711c837cc50a0120f3a188c340f3f4
[email protected] 1.4 e96c75cd0c9b35000b4a3ec12d5dd23ca157e94aee7271a0fe8d8d7c9f2e9096
[email protected] 1.4 faf174414ddc7099360c4ae4d16497b9846cfae71ffad5bbab820bba657f94d3
[email protected] 1.4 b02ae1d5a0d2a5b28f8baa2afcdc7d7090fab051536303cba3ba1f17860da980
[email protected] 1.4 4512389444a767f12211beeb5f2ad165aca4a558e88e8f111affb30b77ed6a5a
[email protected] 1.4 e5c9a29d5ba0f53a49d8b333bfab17bf9878f94e8c3f325f5afacad44bb26fb5

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Immediately Remove Malicious Extensions: If you suspect you have installed any of the identified malicious Firefox extensions, remove them from your browser without delay.
  • Transfer Assets to a New Wallet: Create a brand new cryptocurrency wallet on a secure, clean device that has not been exposed to these extensions. Transfer all your digital assets from the potentially compromised wallet to this new, secure wallet.
  • Revoke Token Approvals: Review and revoke any token approvals granted by the compromised wallet. This prevents attackers from executing unauthorized transactions even if they gain access to your wallet’s signing capabilities.
  • Do Not Reuse Credentials: Never reuse recovery phrases or private keys that may have been exposed. Changing an extension password will not protect you if the underlying recovery phrase or private key has been stolen.
  • Implement Strong Security Practices: Use hardware wallets for storing significant cryptocurrency holdings, enable two-factor authentication (2FA) wherever possible, and be extremely cautious when installing browser extensions, especially those related to financial services.
  • Verify Extension Authenticity: Always verify the authenticity of any browser extension, particularly crypto wallets, by cross-referencing with the official project website. Look for direct links from the official site to the browser’s extension marketplace.
  • Monitor Network Activity: Defenders should monitor network traffic for connections to the identified Cloudflare Worker endpoints and other indicators of compromise to detect and block malicious activity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Tensorlake npm Package Flaw Spreads Shai-Hulud Worm, Steals Dev Secrets

Next Post

Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Agentic AI Red Team Checklist Adds 222 Tests for 20 Attack Categories
October 9, 2026
Warden Stealer Spreads Via Malvertising and Cracked Software
October 9, 2026
MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us