Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminals Target Crypto Users With Fake Firefox Extensions

Cybercriminals Target Crypto Users With Fake Firefox Extensions

Posted on October 8, 2026 By CWS

In a concerning development, cybercriminals have been deploying malicious Firefox extensions to compromise cryptocurrency users. These extensions, totaling 16, were designed to mimic legitimate wallet interfaces and capture sensitive recovery phrases and private keys.

Malicious Extensions and Their Operation

The attackers disguised these extensions as typical wallet utilities and browser tools, embedding hidden code to secretly transmit user data to servers controlled by them. These servers are hosted on Cloudflare Workers, a platform frequently exploited by such malicious campaigns.

The fraudulent extensions replicated the interfaces of popular crypto wallets like Rabby Wallet and OKX Wallet, tricking users into entering their credentials into what appeared to be standard wallet import screens. While Mozilla has removed these harmful extensions from its store as of October 5, 2026, users who have already interacted with them remain vulnerable.

Research Findings and Implications

Research conducted by Socket.dev, released on October 7, revealed the intricacies of these malicious extensions. They identified four major clones imitating Rabby Wallet and 12 smaller ones mimicking OKX-style interfaces. Most of these contained background scripts specifically designed to steal user credentials.

The cybercriminals behind this operation were linked to a previous campaign from August, based on similarities in code and infrastructure. This continuity suggests a persistent threat, with hackers continually adapting their methods to evade detection.

Technical Details and User Impact

Each Rabby clone contained over a thousand files, including wallet import functionalities and transaction interfaces. This extensive mimicry was designed to build trust with users, making the theft of sensitive information more effective. Notably, some parts of the interface retained official links and settings, further enhancing their credibility.

The extensions communicated stolen data via GET requests to the attacker’s server, exposing recovery phrases not only to the attacker but potentially to any system that logs request URLs. OKX-style extensions employed POST requests, sending raw phrases within JSON data, with multiple fallback methods for data transmission.

Users who unknowingly provided their recovery phrases or private keys to these extensions should consider their wallets compromised. Experts recommend creating new wallets on secure devices and transferring assets immediately.

Future Outlook and Recommendations

To mitigate such threats moving forward, users are advised to scrutinize browser extensions carefully, verifying their authenticity before installation. Regular checks of browser profiles and network activity can help identify suspicious extensions early. Additionally, cybersecurity professionals should ensure threat intelligence systems are updated with the latest indicators of compromise.

The ongoing evolution of these threats highlights the importance of maintaining robust digital security practices, especially for those handling cryptocurrency assets. As attackers continue to refine their methods, staying informed and vigilant remains crucial.

Cyber Security News Tags:browser security, Cloudflare Workers, crypto theft, Cryptocurrency, Cybersecurity, Firefox extensions, malicious extensions, Malware, OKX Wallet, Rabby Wallet

Post navigation

Previous Post: Hikvision Camera Flaw Exploited in Cyber Attempts
Next Post: Microsoft Teams Enhances Security Against Deepfake Threats

Related Posts

Microsoft’s New Teams New Admin Role to Manage External Collaboration Settings Microsoft’s New Teams New Admin Role to Manage External Collaboration Settings Cyber Security News
SnappyClient Malware Threatens Windows with Stealthy Data Breaches SnappyClient Malware Threatens Windows with Stealthy Data Breaches Cyber Security News
Enhancing Cybersecurity Intelligence with OpenCTI Enhancing Cybersecurity Intelligence with OpenCTI Cyber Security News
Hackers Using Generative AI ‘ChatGPT’ to Evade Anti-virus Defenses Hackers Using Generative AI ‘ChatGPT’ to Evade Anti-virus Defenses Cyber Security News
Cyberattack Targets South Asian Financial Firm with Custom Malware Cyberattack Targets South Asian Financial Firm with Custom Malware Cyber Security News
Aembit Introduces Identity and Access Management for Agentic AI Aembit Introduces Identity and Access Management for Agentic AI Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Teams Enhances Security Against Deepfake Threats
  • Cybercriminals Target Crypto Users With Fake Firefox Extensions
  • Hikvision Camera Flaw Exploited in Cyber Attempts
  • Ransomware Affiliate Betrayal & Cybersecurity Threats
  • Tensorlake npm Package Exploited to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Teams Enhances Security Against Deepfake Threats
  • Cybercriminals Target Crypto Users With Fake Firefox Extensions
  • Hikvision Camera Flaw Exploited in Cyber Attempts
  • Ransomware Affiliate Betrayal & Cybersecurity Threats
  • Tensorlake npm Package Exploited to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark