Cybersecurity researchers have identified 16 malicious Mozilla Firefox extensions designed to impersonate popular cryptocurrency wallets, specifically Rabby and OKX, with the intent to steal users’ recovery phrases and private keys. These extensions, which masquerade as legitimate wallet portals and browser tools, have been reported to intercept sensitive information during wallet import processes and transmit it to attacker-controlled domains.
According to an analysis by Socket researcher Joseph Edwards, the malicious extensions include names such as “view-focus-bright@webtools.co@6.12.2” and “quick-track-nest@tabtools.co@8.1.18.” Four of these extensions are direct clones of Rabby Wallet, while the remainder targets OKX Wallet. Most of the identified extensions have been found to connect to the “*.icy-star-f45c.workers[.]dev” domain, aiming to exfiltrate mnemonic phrases and private keys.
Continuing Threat Landscape
This discovery is part of an ongoing trend, following a previous wave of malicious extensions documented in August 2026. The threat actors appear to be employing tactics such as rotating package names, versions, and extension IDs while maintaining the same underlying credential-handling logic and network infrastructure. This adaptability suggests a persistent threat to users of cryptocurrency wallets.
As of October 5, 2026, all identified extensions have been removed from the Firefox Add-ons store. Users who may have installed any of these extensions and entered sensitive information are advised to assume their wallets have been compromised. They should create new wallets from a secure system and transfer their assets immediately.
Broader Context of Malicious Extensions
The findings align with a broader pattern of malicious browser extensions targeting users across various platforms, including Google Chrome and Microsoft Edge. Recent reports have highlighted several other malicious extensions, such as “ID-Pay,” which masquerades as a utility for identity verification but is designed to steal session cookies from Google accounts, and a cluster of 32 extensions that harvest user data while posing as productivity tools.
To mitigate risks associated with malicious extensions, users are encouraged to regularly review and remove unnecessary browser extensions. Organizations should implement audits of installed extensions, adopt runtime monitoring strategies, and deploy behavior-based monitoring technologies to detect suspicious activities.
For further details on this issue, refer to the analysis by The Hacker News.


