VYPR
malwarePublished Oct 8, 2026· 1 source

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Recovery Phrases

Cybersecurity researchers have identified 16 malicious Firefox extensions masquerading as popular cryptocurrency wallets like Rabby and OKX, designed to steal users' recovery phrases and private keys.

A wave of malicious browser extensions has been discovered targeting cryptocurrency users, with 16 harmful add-ons found on Mozilla Firefox designed to steal sensitive recovery phrases and private keys. These extensions impersonate legitimate cryptocurrency wallets, including popular options like Rabby Wallet and OKX Wallet, aiming to trick users into compromising their digital assets.

Researchers at Socket detailed how these extensions function as fake wallet portals, desktop utilities, or browser tools. Their malicious code actively intercepts recovery phrases and private keys during the wallet import process. Once captured, these critical credentials are exfiltrated to attacker-controlled infrastructure, specifically identified as a domain associated with Cloudflare Workers (*.icy-star-f45c.workers[.]dev).

Four of the identified extensions were direct clones of Rabby Wallet, while the remaining twelve mimicked OKX Wallet. The threat actors behind this campaign demonstrated a pattern of rotating package names, version numbers, extension IDs, and descriptive text. However, they consistently reused the same wallet interface designs, credential-handling logic, and network infrastructure, indicating a coordinated and persistent effort.

This campaign appears to be a continuation of a similar wave of malicious extensions documented in August 2026, suggesting the threat actors are adapting their tactics to evade detection. By continuously altering their presentation and metadata, they aim to remain hidden on extension marketplaces while continuing their theft operations.

As of October 5, 2026, all 16 malicious extensions have been removed from the Firefox add-on store. However, users who may have installed any of these extensions and entered their recovery phrases or private keys into the fake interfaces are strongly advised to take immediate action. The recommended course of action is to assume their accounts are compromised, create a completely new wallet on a secure, clean system, and transfer any existing assets to the new wallet.

This discovery highlights the persistent threat posed by malicious browser extensions in the cryptocurrency space. Users are urged to exercise extreme caution when installing any browser add-on, especially those related to financial services or security. Always verify the developer, check reviews, and be wary of extensions that request excessive permissions or mimic popular applications.

To mitigate risks, users should regularly audit their installed browser extensions, removing any that are unnecessary or appear suspicious. For organizations, implementing runtime monitoring and behavior-based detection technologies for extensions can provide an additional layer of security against such threats. The ongoing evolution of these attacks underscores the need for continuous vigilance and robust security practices within the digital asset ecosystem.

Synthesized by Vypr AI