Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
16 Harmful Firefox Add-ons Imitate Wallets to Steal Data

16 Harmful Firefox Add-ons Imitate Wallets to Steal Data

Posted on October 8, 2026 By CWS

Cybersecurity experts have identified 16 harmful Mozilla Firefox add-ons that target cryptocurrency users by stealing recovery phrases and private keys. These malicious extensions disguise themselves as legitimate tools but secretly intercept sensitive information during wallet setup processes, passing it to servers controlled by attackers.

Deceptive Appearance and Operation

The identified extensions present themselves as wallet managers and browser utilities. However, their true function is to capture and transmit recovery phrases and private keys to a domain managed by attackers, specifically the “*.icy-star-f45c.workers[.]dev”. This malicious activity is seen as a continuation of similar threats reported earlier in August 2026.

Among the extensions, four are clones of Rabby Wallet, and the rest mimic OKX Wallet, highlighting a targeted approach. The attackers frequently modify package identifiers and visual elements while maintaining the same underlying malicious code and infrastructure.

Impact on Users and Recent Trends

All of the identified extensions were removed by October 5, 2026. Users who have interacted with these extensions and entered genuine recovery phrases should consider their wallet compromised. It is recommended to establish new wallets on secure systems and transfer assets immediately.

This discovery aligns with a broader trend of malicious or dubious browser extensions affecting Firefox, Google Chrome, and Microsoft Edge users. Notable incidents include extensions designed to steal session cookies from Google users and others that secretly track browsing activity or redirect users to phishing sites.

Preventive Measures and Recommendations

To mitigate risks from such malicious add-ons, users should regularly audit their browser extensions, removing any that are unnecessary or suspicious. Organizations managing browser environments are advised to implement runtime monitoring and behavior-based detection systems to identify and neutralize potential threats promptly.

In conclusion, vigilance in managing browser extensions and staying informed about emerging threats are critical steps in safeguarding personal and organizational cyber security. As cyber threats continue to evolve, proactive measures remain the best defense against data breaches and privacy violations.

The Hacker News Tags:browser add-ons, browser security, Cloudflare Workers, Cryptocurrency, Cybersecurity, data theft, Firefox, internet security, malicious extensions, Malware, OKX Wallet, online threats, Privacy, Rabby Wallet, tech news

Post navigation

Previous Post: Hackers Exploit GitHub Poem for AI Malware Control
Next Post: TP-Link Faces Legal Actions Over Security Concerns

Related Posts

European Parliament Member’s Phone Compromised with Pegasus European Parliament Member’s Phone Compromised with Pegasus The Hacker News
Identity Visibility: Key to Secure IAM by 2026 Identity Visibility: Key to Secure IAM by 2026 The Hacker News
UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware The Hacker News
RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains The Hacker News
Critical Vulnerabilities in Protobuf.js Threaten Node.js Security Critical Vulnerabilities in Protobuf.js Threaten Node.js Security The Hacker News
HollowGraph Malware Exploits Microsoft 365 Calendars HollowGraph Malware Exploits Microsoft 365 Calendars The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Nexus Vulnerabilities Expose Networks to Critical Threats
  • TP-Link Faces Legal Actions Over Security Concerns
  • 16 Harmful Firefox Add-ons Imitate Wallets to Steal Data
  • Hackers Exploit GitHub Poem for AI Malware Control
  • Owner Charged in $11M Fraudulent Ransomware Scheme

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Nexus Vulnerabilities Expose Networks to Critical Threats
  • TP-Link Faces Legal Actions Over Security Concerns
  • 16 Harmful Firefox Add-ons Imitate Wallets to Steal Data
  • Hackers Exploit GitHub Poem for AI Malware Control
  • Owner Charged in $11M Fraudulent Ransomware Scheme

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark