[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fp7n-PQOYmi4ne7Fm5fJnoIlixnRr9_V4cNP3NC8oZxc":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"7216bb36-0d6b-43a7-b80c-7cdcacfb6870","16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials","16-malicious-firefox-extensions-steal-cryptocurrency-wallet-credentials-d56480","Socket Threat Research identified a coordinated campaign of 16 Firefox extensions targeting cryptocurrency wallet users. The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers. The campaign is a cryptocurrency wallet credential-stealing operation with a variety of lures: Four large extensions are clones of Rabby Wallet, a popular Ethereum wallet app with 900,000 users on the Chrome Web Store and 500,000 downloads on Google Play. They impersonate Rabby as Raabby WaIIet, hook mnemonic and private-key import paths, and send the raw secret to a Cloudflare Worker using GET query parameters. Twelve smaller extensions are targeted clones of OKX Wallet, the popular DeFi wallet app with over 1,000,000 users on then Chrome Web Store. Eleven register a background script that receives a 12- or 24-word phrase and sends it to a Cloudflare Worker. One, sipoo-grozza@browserweb.com, packages exfiltration code but is broken as shipped: its manifest does not load background.js, and its frontend sends SEED_PHRASE_IMPORT while the packaged background handles only WALLET_SYNC. Fifteen of the extensions contact icy-star-f45c[.]workers[.]dev; the broken variant uses fondationanimalaidrelief[.]workers[.]dev but retains the same frontend and campaign marker. Every manifest declares Firefox data collection permission none, contradicting the code that handles and transmits wallet recovery material. The operators rotate package names, versions, extension IDs, descriptions, and presentation while reusing the same wallet interfaces, credential-handling logic, campaign marker, and network infrastructure. This reuse separates the extensions into a large Rabby wallet clone family and a OKX wallet-phishing family with three background-script variants. Due to reused infrastructure, tactics and targeted lures, we assess with high confidence that this campaign is a continuation of crypto-theft targeted extensions Socket identified in August 2026. Note: As of October 5th, Mozilla has unpublished the malicious extensions. Any user who entered a real recovery phrase or private key into any functioning variant should treat the wallet as compromised: create a new wallet from a clean environment and move assets immediately. Changing only the extension password does not revoke a stolen seed phrase or private key. Affected Extensions # view-focus-bright@webtools.co@6.12.2 quick-track-nest@tabtools.co@8.1.18 vibe-kit-tool@fasttools.co@9.21.9 edge-hub-snap@protools.net@4.12.24 core-hub-peak@neattools.example@8.24.21 sipoo-grozza@browserweb.com@2.1 mozart-seo@webtools.com@1.4 clean-file-bar@neattools.com@4.21.8 clean-net-timer@plugify.example@4.17.1 manager-square@webtools.com@1.4 manager-course@webtools.com@1.4 val-andrew@browserweb.com@1.4 manager-team@browserweb.com@1.4 valory-andrew@browserweb.com@1.4 franklin-uk@browserweb.com@1.4 franklin-uro@browserweb.com@1.4 # Rabby-Clone Family The four large packages are repackaged wallet applications rather than small utility extensions. Each contains 1,114 files and a Webpack application with webpackChunkrabby, Rabby locale material, wallet keyring code, import screens, and transaction UI. The branding is altered to Raabby WaIIet, including index.html, desktop.html, locale names, document titles, and selected application strings. This misspelling is consistent across the otherwise Rabby-derived application and provides a useful static detection string. Rabby Clone Interface The screenshots below show view-focus-bright@webtools.co (version 6.12.2). All four malicious Rabby Wallet clones share this interface. Brand and Infrastructure Inheritance The rebranding is incomplete in ways that strengthen the impersonation finding. The rendered onboarding screen says “Rabby Wallet,” the document title says Raabby WaIIet, and the manifest identifies the author as Debrunk. The application also preserves links to Rabby’s official Chrome Web Store listing, Rabby legal pages, and Rabby mobile applications in the Apple App Store and Google Play. The clone retains upstream Rabby and DeBank service configuration, including api.rabby.io, download.rabby.io, static-assets.rabby.io, static.debank.com, static-assets.debank.com, and matomo.debank.com. During isolated rendering, the application attempted to load an image from static-assets.debank.com and send page-view telemetry to matomo.debank.com; both requests were blocked before contact. The packaged Matomo client uses site ID 2 and derives its visitor identifier from the extension ID. These connections show that the operators repackaged a substantial Rabby codebase and left its upstream assets, service URLs, and analytics intact while injecting a separate credential-theft channel. The Rabby and DeBank hosts are not campaign IOCs and should not be blocked solely because they occur in these packages. The manifests are Firefox Manifest V2 and expose unusually broad capability: persistent background.html page; popup entry point; content script at document_start in all frames; matches file:\u002F\u002F*\u002F*, http:\u002F\u002F*\u002F*, and https:\u002F\u002F*\u002F*; webRequest and webRequestBlocking; arbitrary HTTP and HTTPS host access; explicit access to the malicious Worker endpoint; unsafe-eval and WebAssembly evaluation in the CSP; storage, unlimited storage, active tab, context menu, and notification permissions. The content-script breadth is greater than required for the observed wallet-secret exfiltration. Static analysis did not identify a separate form-grabber claim, so the risk should be described as excessive access rather than unproven browsing-data theft. OKX-Clone Family The compact extensions impersonate a generic wallet portal, but the logo and presentation closely resemble OKX Wallet. Their shared index.html is titled Portal WALLET; the React frontend presents a recovery-phrase import workflow, validates exactly 12 or 24 words, and sends this browser-runtime message: { type: \"SEED_PHRASE_IMPORT\", data: { seedPhrase: rawPhrase }, timestamp: ... } Eleven manifests register background.js and expose a browser-action icon titled Open My Window. Clicking it causes the background script to open index.html in a 400x664 popup window. Fake Wallet Interface The active compact frontend calls the product Portal WALLET, but retains okui-* component classes and links users to OKX Web3’s wallet-password help and Web3 ecosystem terms of service. The package therefore combines generic “Portal” branding with an OKX-derived interface and official OKX destinations, borrowing credibility without claiming a consistent product identity. The shared compact frontend uses polished wallet branding and a familiar onboarding flow to direct victims toward credential entry: # Rabby-Clone Background Hooks At the start of background.js, the malware installs self._lv. This function accepts only: a 12-word string; a 24-word string; or a 64-character hexadecimal string consistent with a raw private key. The function deduplicates values in memory, URL-encodes the raw secret, and sends it to the Worker. Calls to self._lv were inserted directly after legitimate-looking wallet operations, including: importPrivateKey; createKeyringWithMnemonics; mnemonic keyring\u002Faccount import paths. This placement gives the attacker the same secret the wallet accepts, while leaving the underlying wallet flow intact. Rabby-Clone UI Hooks 977.js defines a second exfiltration helper and includes inline copies at UI import paths. Confirmed call sites transmit: the mnemonic passed to generateKeyringWithMnemonic; the seed phrase entered during new-user import; the private key entered during private-key import; the seed phrase used during password-protected keyring creation. The UI helper tags requests with action ui; the background helper uses action import. Multiple hooks improve collection coverage and can generate more than one network request for the same user secret. OKX Clone Handler The shared frontend responsible for phishing a user’s seed phrase passes { seedPhrase } to SEED_PHRASE_IMPORT. The active background variants accept SEED_PHRASE_IMPORT and the legacy alias WALLET_SYNC, trim the secret, reject empty input, require exactly 12 or 24 words, and deduplicate the raw phrase in memory. The resulting request contains the phrase verbatim in field w. For the Web3 Portal family the body is: { \"a\": \"import\", \"s\": \"EQOx7EIPZSNi\", \"k\": \"login\", \"w\": \" \" } The core variant sends the same four fields to a different Worker host. Its background is minified but functionally equivalent. Secret Exfiltration # Rabby-Clone Transport The large family sends a GET request with mode: \"no-cors\" and keepalive: true. If fetch rejects, it retries with XMLHttpRequest. The request format is: [.]workers[.]dev\u002F?w= &s=EQOx7EIPZSNi&k=login&a= &t= Using a GET query exposes the secret not only to the Worker but also to infrastructure request logs, URL logging, and any intermediary that records request targets. OKX-Clone Transport The OKX Web3 Portal variants send the raw phrase via HTTPS POST JSON. Their background logic attempts to read the response and report success to the UI. One extension contained a background script using a more resilient, write-only sequence: navigator.sendBeacon with URL-encoded form data; fetch POST with mode: \"no-cors\" and keepalive; an image-pixel GET fallback. Its comments claim only a hash and word count leave the device, but the payload explicitly assigns the raw phrase to parameter w. The FNV-1a value is used only for deduplication. This comment\u002Fcode contradiction is direct evidence of concealment rather than benign analytics. Broken Variant # sipoo-grozza@browserweb.com@2.1 is not operational through its normal packaged flow for two independent reasons: manifest.json contains no background declaration, so Firefox does not load background.js. The shared frontend emits SEED_PHRASE_IMPORT, while the background routes only WALLET_SYNC. Its browser action has no default popup. The packaged background.js would have registered the click listener that opens index.html, but that script is never loaded. index.html remains web-accessible, yet manually opening it still does not activate the absent\u002Fmismatched handler. This is a delivery defect, not evidence of benign intent. The packaged code still contains explicit raw-secret collection, a remote destination, and three exfiltration transports. A repaired manifest and event case would make it functional. Campaign Attribution # The extensions separate into two closely related implementation groups: Rabby clone — four extensions: All 1,108 non-manifest, non-signature files are identical. The extensions collect 12- or 24-word mnemonics and 64-hex private keys, then send them to silent-wind-get.icy-star-f45c.workers[.]dev. Their exfiltration hooks load normally, and the endpoint is covered by explicit host permission. OKX Clone Web3 Portal — ten extensions: All 20 non-manifest, non-signature files are identical. These extensions collect 12- or 24-word mnemonics through green-firefly-ab28.icy-star-f45c[.]workers[.]dev , small-boat-969c.icy-star-f45c[.]workers[.]devor flat-wildflower-f954.fondationanimalaidrelief[.]workers[.]dev. Their handlers load, but their manifests omit the remote host. Additional relationships directly observed: One campaign marker EQOx7EIPZSNi appears in every family. This marker also surfaced in our previous research on this threat actor. Fifteen of the sixteen extensions share the same login key and import action schema. Fifteen of the sixteen extensions use three Worker names beneath the exact suffix icy-star-f45c[.]workers[.]dev. All twelve OKX clone extensions share an identical frontend and 19\u002F20 non-metadata files. Ten OKX clone samples have an identical 4,160-byte background.js. The four Rabby clone samples have an identical background.js and application files outside manifest\u002Fsignature metadata. The compact package names, versions, extension IDs, and descriptions vary while payload code remains fixed. These facts support builder pipeline with at least two generated campaign variants. Detection Opportunities # High-confidence static detections: Fake brand string Raabby WaIIet; message types SEED_PHRASE_IMPORT and WALLET_SYNC adjacent to raw seedPhrase handling; JSON fields a, s, k, w with values import, EQOx7EIPZSNi, login, and a 12\u002F24-word phrase; GET parameters w, s, k, a, and t sent to the Workers endpoint; manifests declaring data_collection_permissions.required = [\"none\"] while code transmits wallet recovery material; identical background.js hashes listed below. Network detections should account for the secret-bearing query or body without logging the actual secret into additional security systems. Match host, path, method, parameter names, and campaign marker; redact field w. Response Recommendations # For an affected user: Disconnect the system from wallet workflows and remove every listed extension ID. From a clean device, create a new wallet with a new recovery phrase. Transfer assets and revoke token approvals associated with the exposed wallet. Treat every account derived from the exposed mnemonic as compromised. Do not rely on changing the extension password; it does not invalidate the mnemonic or private key. Review browser profiles and synchronized extension state on every Firefox device. For defenders: Block the listed extension IDs and XPI hashes. Search extension inventories for the four background.js hashes and the campaign marker. Search proxy\u002FDNS telemetry for the three Worker namespaces, while preventing secret field w from being copied into case notes or alerts. Preserve the original XPI and browser profile for incident scope, but never run the extension on an analyst host. Hunt for other extension packages with the shared compact frontend hash or identical Rabby-derived file set. # Campaign Code Markers EQOx7EIPZSNi Raabby WaIIet SEED_PHRASE_IMPORT WALLET_SYNC Network Indicators hxxps:\u002F\u002Fsilent-wind-get[.]icy-star-f45c[.]workers[.]dev\u002F hxxps:\u002F\u002Fsmall-boat-969c[.]icy-star-f45c[.]workers[.]dev\u002F hxxps:\u002F\u002Fgreen-firefly-ab28[.]icy-star-f45c[.]workers[.]dev\u002F hxxps:\u002F\u002Fflat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev\u002F Shared File Hashes Rabby-clone background.js SHA-256: 7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799 OKX Clone core background.js SHA-256: da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd Broken variant background.js SHA-256: be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897 OKX Clone Web3 Portal background.js SHA-256: c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f Shared compact frontend SHA-256: eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf Extension IDs and XPI SHA-256 Hashes view-focus-bright@webtools.co, version 6.12.2 — 2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51 quick-track-nest@tabtools.co, version 8.1.18 — 225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b vibe-kit-tool@fasttools.co, version 9.21.9 — 6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8 edge-hub-snap@protools.net, version 4.12.24 — 8906dd85b0991fac14e5973b3f3f61d93ef1101504cb5867a004c762ee184ef7 core-hub-peak@neattools.example, version 8.24.21 — 9fea0ee3c81047f5e50eeb3a2ab2a7cd70357f3e49944b7079ab3e90c9ea0e8b sipoo-grozza@browserweb.com, version 2.1 — 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35 mozart-seo@webtools.com, version 1.4 — 635b31b4a19b5673fcbe0fedeb3f7ed2c27fddb739685f19ca5f3d1f1d7f0083 clean-file-bar@neattools.com, version 4.21.8 — d9432e41e0401715bce4ce11f4a7104d94fab1ec89be553ba57a2097e418c1a1 clean-net-timer@plugify.example, version 4.17.1 — 458e7255438f15aaede02fd7f8fcfdf762aa6e08608b9546fe8aa8aa399c76b7 manager-square@webtools.com, version 1.4 — bb8f60b3f77d96adc93bf0515b34df7c5f1f560a9f6d0c353b7d849609e3557d manager-course@webtools.com, version 1.4 — 71ec70479ab78efb1e1f9507f8ff7348d5711c837cc50a0120f3a188c340f3f4 val-andrew@browserweb.com, version 1.4 — e96c75cd0c9b35000b4a3ec12d5dd23ca157e94aee7271a0fe8d8d7c9f2e9096 manager-team@browserweb.com, version 1.4 — faf174414ddc7099360c4ae4d16497b9846cfae71ffad5bbab820bba657f94d3 valory-andrew@browserweb.com, version 1.4 — b02ae1d5a0d2a5b28f8baa2afcdc7d7090fab051536303cba3ba1f17860da980 franklin-uk@browserweb.com, version 1.4 — 4512389444a767f12211beeb5f2ad165aca4a558e88e8f111affb30b77ed6a5a franklin-uro@browserweb.com, version 1.4 — e5c9a29d5ba0f53a49d8b333bfab17bf9878f94e8c3f325f5afacad44bb26fb5","Socket Threat Research discovered a coordinated campaign of 16 malicious Firefox extensions targeting cryptocurrency wallet users by impersonating legitimate wallets (Rabby and OKX). The extensions intercept recovery phrases and private keys during wallet import workflows and exfiltrate them to attacker-controlled Cloudflare Workers. Mozilla has unpublished all extensions as of October 5th; affected users should immediately create new wallets from clean environments and migrate assets.","Socket identifies 16 malicious Firefox extensions stealing crypto wallet recovery phrases and private keys via cloned","BackResearchSecurity News16 Malicious Firefox Extensions Steal Cryptocurrency Wallet CredentialsSocket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.Joseph EdwardsOct 7, 2026|9 min readExport IOCs25Socket Threat Research identified a coordinated campaign of 16 Firefox extensions targeting cryptocurrency wallet users. The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers.The campaign is a cryptocurrency wallet credential-stealing operation with a variety of lures:Four large extensions are clones of Rabby Wallet, a popular Ethereum wallet app with 900,000 users on the Chrome Web Store and 500,000 downloads on Google Play. They impersonate Rabby as Raabby WaIIet, hook mnemonic and private-key import paths, and send the raw secret to a Cloudflare Worker using GET query parameters.Twelve smaller extensions are targeted clones of OKX Wallet, the popular DeFi wallet app with over 1,000,000 users on then Chrome Web Store. Eleven register a background script that receives a 12- or 24-word phrase and sends it to a Cloudflare Worker. One, sipoo-grozza@browserweb.com, packages exfiltration code but is broken as shipped: its manifest does not load background.js, and its frontend sends SEED_PHRASE_IMPORT while the packaged background handles only WALLET_SYNC.Fifteen of the extensions contact icy-star-f45c[.]workers[.]dev; the broken variant uses fondationanimalaidrelief[.]workers[.]dev but retains the same frontend and campaign marker.Every manifest declares Firefox data collection permission none, contradicting the code that handles and transmits wallet recovery material.The operators rotate package names, versions, extension IDs, descriptions, and presentation while reusing the same wallet interfaces, credential-handling logic, campaign marker, and network infrastructure. This reuse separates the extensions into a large Rabby wallet clone family and a OKX wallet-phishing family with three background-script variants. Due to reused infrastructure, tactics and targeted lures, we assess with high confidence that this campaign is a continuation of crypto-theft targeted extensions Socket identified in August 2026.Note: As of October 5th, Mozilla has unpublished the malicious extensions. Any user who entered a real recovery phrase or private key into any functioning variant should treat the wallet as compromised: create a new wallet from a clean environment and move assets immediately. Changing only the extension password does not revoke a stolen seed phrase or private key.Affected Extensions#view-focus-bright@webtools.co@6.12.2quick-track-nest@tabtools.co@8.1.18vibe-kit-tool@fasttools.co@9.21.9edge-hub-snap@protools.net@4.12.24core-hub-peak@neattools.example@8.24.21sipoo-grozza@browserweb.com@2.1mozart-seo@webtools.com@1.4clean-file-bar@neattools.com@4.21.8clean-net-timer@plugify.example@4.17.1manager-square@webtools.com@1.4manager-course@webtools.com@1.4val-andrew@browserweb.com@1.4manager-team@browserweb.com@1.4valory-andrew@browserweb.com@1.4franklin-uk@browserweb.com@1.4franklin-uro@browserweb.com@1.4Installation and Presentation#Rabby-Clone Family#The four large packages are repackaged wallet applications rather than small utility extensions. Each contains 1,114 files and a Webpack application with webpackChunkrabby, Rabby locale material, wallet keyring code, import screens, and transaction UI.The branding is altered to Raabby WaIIet, including index.html, desktop.html, locale names, document titles, and selected application strings. This misspelling is consistent across the otherwise Rabby-derived application and provides a useful static detection string.Rabby Clone Interface#The screenshots below show view-focus-bright@webtools.co (version 6.12.2). All four malicious Rabby Wallet clones share this interface.Brand and Infrastructure Inheritance#The rebranding is incomplete in ways that strengthen the impersonation finding. The rendered onboarding screen says “Rabby Wallet,” the document title says Raabby WaIIet, and the manifest identifies the author as Debrunk. The application also preserves links to Rabby’s official Chrome Web Store listing, Rabby legal pages, and Rabby mobile applications in the Apple App Store and Google Play.The clone retains upstream Rabby and DeBank service configuration, including api.rabby.io, download.rabby.io, static-assets.rabby.io, static.debank.com, static-assets.debank.com, and matomo.debank.com. During isolated rendering, the application attempted to load an image from static-assets.debank.com and send page-view telemetry to matomo.debank.com; both requests were blocked before contact. The packaged Matomo client uses site ID 2 and derives its visitor identifier from the extension ID.These connections show that the operators repackaged a substantial Rabby codebase and left its upstream assets, service URLs, and analytics intact while injecting a separate credential-theft channel. The Rabby and DeBank hosts are not campaign IOCs and should not be blocked solely because they occur in these packages.The manifests are Firefox Manifest V2 and expose unusually broad capability:persistent background.html page;popup entry point;content script at document_start in all frames;matches file:\u002F\u002F*\u002F*, http:\u002F\u002F*\u002F*, and https:\u002F\u002F*\u002F*;webRequest and webRequestBlocking;arbitrary HTTP and HTTPS host access;explicit access to the malicious Worker endpoint;unsafe-eval and WebAssembly evaluation in the CSP;storage, unlimited storage, active tab, context menu, and notification permissions.The content-script breadth is greater than required for the observed wallet-secret exfiltration. Static analysis did not identify a separate form-grabber claim, so the risk should be described as excessive access rather than unproven browsing-data theft.OKX-Clone Family#The compact extensions impersonate a generic wallet portal, but the logo and presentation closely resemble OKX Wallet. Their shared index.html is titled Portal WALLET; the React frontend presents a recovery-phrase import workflow, validates exactly 12 or 24 words, and sends this browser-runtime message:JavaScript{ type: \"SEED_PHRASE_IMPORT\", data: { seedPhrase: rawPhrase }, timestamp: ... }Eleven manifests register background.js and expose a browser-action icon titled Open My Window. Clicking it causes the background script to open index.html in a 400x664 popup window.Fake Wallet Interface#The active compact frontend calls the product Portal WALLET, but retains okui-* component classes and links users to OKX Web3’s wallet-password help and Web3 ecosystem terms of service. The package therefore combines generic “Portal” branding with an OKX-derived interface and official OKX destinations, borrowing credibility without claiming a consistent product identity.The shared compact frontend uses polished wallet branding and a familiar onboarding flow to direct victims toward credential entry:Secret Collection#Rabby-Clone Background Hooks#At the start of background.js, the malware installs self._lv. This function accepts only:a 12-word string;a 24-word string; ora 64-character hexadecimal string consistent with a raw private key.The function deduplicates values in memory, URL-encodes the raw secret, and sends it to the Worker. Calls to self._lv were inserted directly after legitimate-looking wallet operations, including:importPrivateKey;createKeyringWithMnemonics;mnemonic keyring\u002Faccount import paths.This placement gives the attacker the same secret the wallet accepts, while leaving the underlying wallet flow intact.Rabby-Clone UI Hooks#977.js defines a second exfiltration helper and includes inline copies at UI import paths. Confirmed call sites transmit:the mnemonic passed to generateKeyringWithMnemonic;the seed phrase entered d","https:\u002F\u002Fsocket.dev\u002Fblog\u002Ffirefox-crypto-wallet-stealers?utm_medium=feed","https:\u002F\u002Fcdn.sanity.io\u002Fimages\u002Fcgdhsj6q\u002Fproduction\u002F90384c272b56dc3ffa89f338c19c2bbaa3445ed6-1672x941.png?w=1000&q=95&fit=max&auto=format","2026-10-07T15:43:09.619+00:00","2026-10-07T20:00:24.446416+00:00",9,[18,21,23,25,28,30],{"name":19,"type":20},"Firefox","product",{"name":22,"type":20},"Rabby Wallet",{"name":24,"type":20},"OKX Wallet",{"name":26,"type":27},"Cloudflare","vendor",{"name":29,"type":27},"Mozilla",{"name":31,"type":32},"Cloudflare Workers","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":33,"icon":35,"name":36,"slug":37},null,"Malware","malware",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"0493c7e9-989a-4692-b4e6-136f5ec09675","Cryptography","cryptography",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57,61,64,66,69,73,76,79,82,85],{"type":58,"value":59,"context":60},"domain","silent-wind-get.icy-star-f45c.workers.dev","Rabby-clone C2 endpoint for credential exfiltration via GET requests",{"type":58,"value":62,"context":63},"small-boat-969c.icy-star-f45c.workers.dev","OKX-clone C2 endpoint for credential exfiltration",{"type":58,"value":65,"context":63},"green-firefly-ab28.icy-star-f45c.workers.dev",{"type":58,"value":67,"context":68},"flat-wildflower-f954.fondationanimalaidrelief.workers.dev","Broken variant OKX-clone C2 endpoint",{"type":70,"value":71,"context":72},"hash_sha256","7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799","Rabby-clone background.js shared across all four Rabby-clone extensions",{"type":70,"value":74,"context":75},"da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd","OKX-clone core background.js variant",{"type":70,"value":77,"context":78},"be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897","Broken OKX-clone variant background.js",{"type":70,"value":80,"context":81},"c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f","OKX-clone Web3 Portal background.js variant",{"type":70,"value":83,"context":84},"eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf","Shared OKX-clone frontend across all 12 OKX variants",{"type":37,"value":86,"context":87},"Raabby WaIIet","Malicious Firefox extension campaign cloning Rabby Wallet"]