In a concerning development, cybercriminals have been deploying malicious Firefox extensions to compromise cryptocurrency users. These extensions, totaling 16, were designed to mimic legitimate wallet interfaces and capture sensitive recovery phrases and private keys.
Malicious Extensions and Their Operation
The attackers disguised these extensions as typical wallet utilities and browser tools, embedding hidden code to secretly transmit user data to servers controlled by them. These servers are hosted on Cloudflare Workers, a platform frequently exploited by such malicious campaigns.
The fraudulent extensions replicated the interfaces of popular crypto wallets like Rabby Wallet and OKX Wallet, tricking users into entering their credentials into what appeared to be standard wallet import screens. While Mozilla has removed these harmful extensions from its store as of October 5, 2026, users who have already interacted with them remain vulnerable.
Research Findings and Implications
Research conducted by Socket.dev, released on October 7, revealed the intricacies of these malicious extensions. They identified four major clones imitating Rabby Wallet and 12 smaller ones mimicking OKX-style interfaces. Most of these contained background scripts specifically designed to steal user credentials.
The cybercriminals behind this operation were linked to a previous campaign from August, based on similarities in code and infrastructure. This continuity suggests a persistent threat, with hackers continually adapting their methods to evade detection.
Technical Details and User Impact
Each Rabby clone contained over a thousand files, including wallet import functionalities and transaction interfaces. This extensive mimicry was designed to build trust with users, making the theft of sensitive information more effective. Notably, some parts of the interface retained official links and settings, further enhancing their credibility.
The extensions communicated stolen data via GET requests to the attacker’s server, exposing recovery phrases not only to the attacker but potentially to any system that logs request URLs. OKX-style extensions employed POST requests, sending raw phrases within JSON data, with multiple fallback methods for data transmission.
Users who unknowingly provided their recovery phrases or private keys to these extensions should consider their wallets compromised. Experts recommend creating new wallets on secure devices and transferring assets immediately.
Future Outlook and Recommendations
To mitigate such threats moving forward, users are advised to scrutinize browser extensions carefully, verifying their authenticity before installation. Regular checks of browser profiles and network activity can help identify suspicious extensions early. Additionally, cybersecurity professionals should ensure threat intelligence systems are updated with the latest indicators of compromise.
The ongoing evolution of these threats highlights the importance of maintaining robust digital security practices, especially for those handling cryptocurrency assets. As attackers continue to refine their methods, staying informed and vigilant remains crucial.
