Back to Feed
MalwareOct 7, 2026

16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials

Socket identifies 16 malicious Firefox extensions stealing crypto wallet recovery phrases and private keys via cloned

Summary

Socket Threat Research discovered a coordinated campaign of 16 malicious Firefox extensions targeting cryptocurrency wallet users by impersonating legitimate wallets (Rabby and OKX). The extensions intercept recovery phrases and private keys during wallet import workflows and exfiltrate them to attacker-controlled Cloudflare Workers. Mozilla has unpublished all extensions as of October 5th; affected users should immediately create new wallets from clean environments and migrate assets.

Full text

BackResearchSecurity News16 Malicious Firefox Extensions Steal Cryptocurrency Wallet CredentialsSocket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.Joseph EdwardsOct 7, 2026|9 min readExport IOCs25Socket Threat Research identified a coordinated campaign of 16 Firefox extensions targeting cryptocurrency wallet users. The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers.The campaign is a cryptocurrency wallet credential-stealing operation with a variety of lures:Four large extensions are clones of Rabby Wallet, a popular Ethereum wallet app with 900,000 users on the Chrome Web Store and 500,000 downloads on Google Play. They impersonate Rabby as Raabby WaIIet, hook mnemonic and private-key import paths, and send the raw secret to a Cloudflare Worker using GET query parameters.Twelve smaller extensions are targeted clones of OKX Wallet, the popular DeFi wallet app with over 1,000,000 users on then Chrome Web Store. Eleven register a background script that receives a 12- or 24-word phrase and sends it to a Cloudflare Worker. One, sipoo-grozza@browserweb.com, packages exfiltration code but is broken as shipped: its manifest does not load background.js, and its frontend sends SEED_PHRASE_IMPORT while the packaged background handles only WALLET_SYNC.Fifteen of the extensions contact icy-star-f45c[.]workers[.]dev; the broken variant uses fondationanimalaidrelief[.]workers[.]dev but retains the same frontend and campaign marker.Every manifest declares Firefox data collection permission none, contradicting the code that handles and transmits wallet recovery material.The operators rotate package names, versions, extension IDs, descriptions, and presentation while reusing the same wallet interfaces, credential-handling logic, campaign marker, and network infrastructure. This reuse separates the extensions into a large Rabby wallet clone family and a OKX wallet-phishing family with three background-script variants. Due to reused infrastructure, tactics and targeted lures, we assess with high confidence that this campaign is a continuation of crypto-theft targeted extensions Socket identified in August 2026.Note: As of October 5th, Mozilla has unpublished the malicious extensions. Any user who entered a real recovery phrase or private key into any functioning variant should treat the wallet as compromised: create a new wallet from a clean environment and move assets immediately. Changing only the extension password does not revoke a stolen seed phrase or private key.Affected Extensions#view-focus-bright@webtools.co@6.12.2quick-track-nest@tabtools.co@8.1.18vibe-kit-tool@fasttools.co@9.21.9edge-hub-snap@protools.net@4.12.24core-hub-peak@neattools.example@8.24.21sipoo-grozza@browserweb.com@2.1mozart-seo@webtools.com@1.4clean-file-bar@neattools.com@4.21.8clean-net-timer@plugify.example@4.17.1manager-square@webtools.com@1.4manager-course@webtools.com@1.4val-andrew@browserweb.com@1.4manager-team@browserweb.com@1.4valory-andrew@browserweb.com@1.4franklin-uk@browserweb.com@1.4franklin-uro@browserweb.com@1.4Installation and Presentation#Rabby-Clone Family#The four large packages are repackaged wallet applications rather than small utility extensions. Each contains 1,114 files and a Webpack application with webpackChunkrabby, Rabby locale material, wallet keyring code, import screens, and transaction UI.The branding is altered to Raabby WaIIet, including index.html, desktop.html, locale names, document titles, and selected application strings. This misspelling is consistent across the otherwise Rabby-derived application and provides a useful static detection string.Rabby Clone Interface#The screenshots below show view-focus-bright@webtools.co (version 6.12.2). All four malicious Rabby Wallet clones share this interface.Brand and Infrastructure Inheritance#The rebranding is incomplete in ways that strengthen the impersonation finding. The rendered onboarding screen says “Rabby Wallet,” the document title says Raabby WaIIet, and the manifest identifies the author as Debrunk. The application also preserves links to Rabby’s official Chrome Web Store listing, Rabby legal pages, and Rabby mobile applications in the Apple App Store and Google Play.The clone retains upstream Rabby and DeBank service configuration, including api.rabby.io, download.rabby.io, static-assets.rabby.io, static.debank.com, static-assets.debank.com, and matomo.debank.com. During isolated rendering, the application attempted to load an image from static-assets.debank.com and send page-view telemetry to matomo.debank.com; both requests were blocked before contact. The packaged Matomo client uses site ID 2 and derives its visitor identifier from the extension ID.These connections show that the operators repackaged a substantial Rabby codebase and left its upstream assets, service URLs, and analytics intact while injecting a separate credential-theft channel. The Rabby and DeBank hosts are not campaign IOCs and should not be blocked solely because they occur in these packages.The manifests are Firefox Manifest V2 and expose unusually broad capability:persistent background.html page;popup entry point;content script at document_start in all frames;matches file://*/*, http://*/*, and https://*/*;webRequest and webRequestBlocking;arbitrary HTTP and HTTPS host access;explicit access to the malicious Worker endpoint;unsafe-eval and WebAssembly evaluation in the CSP;storage, unlimited storage, active tab, context menu, and notification permissions.The content-script breadth is greater than required for the observed wallet-secret exfiltration. Static analysis did not identify a separate form-grabber claim, so the risk should be described as excessive access rather than unproven browsing-data theft.OKX-Clone Family#The compact extensions impersonate a generic wallet portal, but the logo and presentation closely resemble OKX Wallet. Their shared index.html is titled Portal WALLET; the React frontend presents a recovery-phrase import workflow, validates exactly 12 or 24 words, and sends this browser-runtime message:JavaScript{ type: "SEED_PHRASE_IMPORT", data: { seedPhrase: rawPhrase }, timestamp: ... }Eleven manifests register background.js and expose a browser-action icon titled Open My Window. Clicking it causes the background script to open index.html in a 400x664 popup window.Fake Wallet Interface#The active compact frontend calls the product Portal WALLET, but retains okui-* component classes and links users to OKX Web3’s wallet-password help and Web3 ecosystem terms of service. The package therefore combines generic “Portal” branding with an OKX-derived interface and official OKX destinations, borrowing credibility without claiming a consistent product identity.The shared compact frontend uses polished wallet branding and a familiar onboarding flow to direct victims toward credential entry:Secret Collection#Rabby-Clone Background Hooks#At the start of background.js, the malware installs self._lv. This function accepts only:a 12-word string;a 24-word string; ora 64-character hexadecimal string consistent with a raw private key.The function deduplicates values in memory, URL-encodes the raw secret, and sends it to the Worker. Calls to self._lv were inserted directly after legitimate-looking wallet operations, including:importPrivateKey;createKeyringWithMnemonics;mnemonic keyring/account import paths.This placement gives the attacker the same secret the wallet accepts, while leaving the underlying wallet flow intact.Rabby-Clone UI Hooks#977.js defines a second exfiltration helper and includes inline copies at UI import paths. Confirmed call sites transmit:the mnemonic passed to generateKeyringWithMnemonic;the seed phrase entered d

Indicators of Compromise

  • domain — silent-wind-get.icy-star-f45c.workers.dev
  • domain — small-boat-969c.icy-star-f45c.workers.dev
  • domain — green-firefly-ab28.icy-star-f45c.workers.dev
  • domain — flat-wildflower-f954.fondationanimalaidrelief.workers.dev
  • hash_sha256 — 7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799
  • hash_sha256 — da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd
  • hash_sha256 — be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897
  • hash_sha256 — c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f
  • hash_sha256 — eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf
  • malware — Raabby WaIIet

Entities

Firefox (product)Rabby Wallet (product)OKX Wallet (product)Cloudflare (vendor)Mozilla (vendor)Cloudflare Workers (technology)