16 malicious Firefox extensions impersonate Rabby and OKX wallets to steal cryptocurrency recovery phrases

Published:

Cybersecurity researchers have identified 16 malicious Mozilla Firefox extensions designed to impersonate popular cryptocurrency wallets, specifically Rabby and OKX, with the intent to steal users’ recovery phrases and private keys. These extensions, which masquerade as legitimate wallet portals and browser tools, have been reported to intercept sensitive information during wallet import processes and transmit it to attacker-controlled domains.

According to an analysis by Socket researcher Joseph Edwards, the malicious extensions include names such as “view-focus-bright@webtools.co@6.12.2” and “quick-track-nest@tabtools.co@8.1.18.” Four of these extensions are direct clones of Rabby Wallet, while the remainder targets OKX Wallet. Most of the identified extensions have been found to connect to the “*.icy-star-f45c.workers[.]dev” domain, aiming to exfiltrate mnemonic phrases and private keys.

Continuing Threat Landscape

This discovery is part of an ongoing trend, following a previous wave of malicious extensions documented in August 2026. The threat actors appear to be employing tactics such as rotating package names, versions, and extension IDs while maintaining the same underlying credential-handling logic and network infrastructure. This adaptability suggests a persistent threat to users of cryptocurrency wallets.

As of October 5, 2026, all identified extensions have been removed from the Firefox Add-ons store. Users who may have installed any of these extensions and entered sensitive information are advised to assume their wallets have been compromised. They should create new wallets from a secure system and transfer their assets immediately.

Broader Context of Malicious Extensions

The findings align with a broader pattern of malicious browser extensions targeting users across various platforms, including Google Chrome and Microsoft Edge. Recent reports have highlighted several other malicious extensions, such as “ID-Pay,” which masquerades as a utility for identity verification but is designed to steal session cookies from Google accounts, and a cluster of 32 extensions that harvest user data while posing as productivity tools.

To mitigate risks associated with malicious extensions, users are encouraged to regularly review and remove unnecessary browser extensions. Organizations should implement audits of installed extensions, adopt runtime monitoring strategies, and deploy behavior-based monitoring technologies to detect suspicious activities.

For further details on this issue, refer to the analysis by The Hacker News.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

US withdrawal of B-1 bombers from RAF Fairford highlights need for enhanced base defenses against drone threats

In a significant operational shift, the United States has withdrawn a dozen B-1 Lancer bombers from RAF Fairford in southern England, a move prompted...

Web3 command-and-control evolution enhances cloud supply chain attack strategies, reveals Unit 42 analysis

Recent analysis by Unit 42 reveals a significant evolution in the command-and-control (C2) strategies employed by threat actors, particularly in the context of cloud...

Cybersecurity leaders in the UAE urged to secure machine identities amid cloud expansion

As the adoption of cloud services and automation accelerates in the UAE, cybersecurity leaders are increasingly urged to focus on securing machine identities. Justin...

Federal contractors may soon face new cybersecurity rules for handling controlled unclassified information

Federal contractors handling sensitive information may soon face significant changes in cybersecurity regulations concerning controlled unclassified information (CUI). Proposed federal regulations, which could be...