Hackers Use Fake Firefox Wallet Extensions to Steal Crypto Recovery Phrases
Sixteen malicious Firefox extensions impersonated crypto wallets and stole recovery phrases via Cloudflare Workers.
Socket.dev identified 16 malicious Firefox extensions, four large Rabby Wallet clones and 12 smaller OKX-style add-ons, that captured 12- or 24-word recovery phrases and private keys. Mozilla had removed them from its marketplace by October 5, 2026, but phrases already submitted remain compromised. Rabby clones sent secrets in GET request URLs to Cloudflare Workers, while OKX-style handlers used HTTPS POST. Socket linked the activity to an August campaign through shared code, infrastructure, and the marker EQOx7EIPZSNi.
- Sixteen Firefox add-ons cloned Rabby and OKX wallet import screens.
- Mozilla removed the listings by October 5, 2026.
- Secrets were sent to Cloudflare Workers in GET URLs or JSON POSTs.
- Anyone who entered a real seed phrase should create a new wallet.
- Socket linked the packages to an August campaign via shared infrastructure.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | flat-wildflower-f954.fondationanimalaidrelief.workers.dev | .]dev/ OKX-style secret collection Network endpoint hxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/ Endpoint packaged in the broken variant Campaign mar |
| domain | green-firefly-ab28.icy-star-f45c.workers.dev | .]dev/ OKX-style secret collection Network endpoint hxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/ OKX-style secret collection Network endpoint hxxps:/ |
| domain | silent-wind-get.icy-star-f45c.workers.dev | Indicators Type Indicator Purpose Network endpoint hxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/ Rabby-clone secret collection Network endpoint hxxps |
| domain | small-boat-969c.icy-star-f45c.workers.dev | dev/ Rabby-clone secret collection Network endpoint hxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/ OKX-style secret collection Network endpoint hxxps:/ |
| sha256 | 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35 | f3e49944b7079ab3e90c9ea0e8b sipoo-grozza@browserweb.com 2.1 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35 mozart-seo@webtools.com 1.4 635b31b4a19b5673fcbe0fedeb3f7ed |
Full article967 words · extracted from cybersecuritynews.com · click to collapse
Hackers have used 16 malicious Firefox extensions to target cryptocurrency users with fake wallet screens that capture recovery phrases and private keys.
The add-ons posed as wallet portals, desktop tools, and browser utilities, while hidden code attempted to send the secrets to attacker-controlled Cloudflare Workers.
The campaign copied interfaces from Rabby Wallet and OKX Wallet, turning familiar wallet import steps into traps. Mozilla had removed the malicious extensions from its marketplace by October 5, 2026.
However, removal does not protect anyone who already entered a recovery phrase or private key into a working version. Researchers from Socket.dev identified the malware and published their findings on October 7.
Their analysis found four large Rabby clones and 12 smaller OKX-style extensions. Eleven smaller packages loaded credential-stealing background scripts; one contained similar theft code but could not run it through its normal packaged workflow.
Socket linked the activity with high confidence to an August campaign based on shared code, infrastructure, and a common tracking marker.
The earlier Firefox wallet theft campaign also used fake wallet interfaces and Cloudflare Workers to collect secrets, showing how attackers can keep publishing related packages under changing names.
Hackers Use Fake Firefox Wallet Extensions
Each Rabby clone contained 1,114 files, including wallet import screens, account management code, and transaction interfaces.
Rather than building a simple phishing page, the operators copied a substantial wallet application and added theft functions. Some official Rabby links and DeBank service settings remained, helping the altered software look more convincing.
The stolen branding was inconsistent: the welcome screen still displayed Rabby Wallet, while other parts used a misspelled name. More importantly, malicious functions were placed directly after private-key and recovery-phrase import operations.
They accepted 12-word or 24-word phrases and 64-character hexadecimal private keys, copying the same secrets the wallet processed. This approach exploits trust in a familiar screen rather than proving a flaw in the real wallet service.
Similar fake crypto wallet screens have appeared in separate malware campaigns, where convincing recovery prompts persuade users to surrender secrets. Here, the copied application could continue its wallet workflow while the theft code ran alongside it.
.webp)
The smaller extensions displayed an OKX-derived interface under generic portal branding. Their import form checked for exactly 12 or 24 words, then passed the entered phrase to a background handler.
That handler removed surrounding spaces, rejected empty input, and avoided sending repeated phrases already seen during the running session.
Secrets Sent Through Cloudflare Workers
The Rabby clones sent secrets inside GET request URLs, with a second request method available if the first failed. This exposed recovery material not only to the attacker’s endpoint but also to systems that record request URLs.
The active OKX-style handlers instead sent raw phrases in HTTPS POST requests containing JSON data. One packaged background script offered three sending methods: a browser beacon, a POST request, and an image-based GET fallback.
Its comments claimed that only a hash and word count left the device. Socket found that the payload contained the full phrase; the hash served only to prevent duplicate submissions.
The broken extension lacked the manifest entry needed to load its background script, and its interface sent a message the handler did not accept. That limits claims about its operation, not its intent.
Separate TronLink wallet impersonation attacks likewise show how copied wallet interfaces can become credential traps, although those attacks used different delivery and collection methods.
Every extension declared that it collected no data, contradicting the secret-handling code. The Rabby clones also requested broad browser access.
However, Socket’s static analysis did not establish a separate form-grabbing capability, so the confirmed finding remains wallet-secret theft rather than wider browsing-data collection.
Legitimate Rabby and DeBank domains retained in the packages are not campaign indicators. Anyone who entered a real phrase or private key into a working variant should treat the wallet as compromised.
Socket recommends removing the extensions, creating a new wallet on a clean device, moving assets, and revoking relevant token approvals. Changing the extension password cannot invalidate a stolen recovery phrase or private key.
Defenders should check extension inventories, browser profiles, synchronized add-ons, and network records against the indicators below.
Searches should match destination hosts, request patterns, hashes, and campaign markers without copying stolen phrases into alerts or case notes.
The secret-bearing field should be redacted. Preserve suspicious packages for investigation, but do not run them on an analyst’s normal workstation.
Indicators of compromise (IoCs):-
Network and Code Indicators
| Type | Indicator | Purpose |
|---|---|---|
| Network endpoint | hxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/ | Rabby-clone secret collection |
| Network endpoint | hxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/ | OKX-style secret collection |
| Network endpoint | hxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/ | OKX-style secret collection |
| Network endpoint | hxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/ | Endpoint packaged in the broken variant |
| Campaign marker | EQOx7EIPZSNi | Shared campaign token |
| Fake branding | Raabby WaIIet | Rabby-clone detection string |
| Runtime message | SEED_PHRASE_IMPORT | Recovery-phrase submission |
| Runtime message | WALLET_SYNC | Legacy message handled by theft code |
| File or Component | SHA-256 |
|---|---|
Rabby-clone background.js | 7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799 |
OKX core background.js | da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd |
Broken variant background.js | be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897 |
OKX Web3 Portal background.js | c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f |
| Shared compact frontend | eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf |
Extension IDs and Package Hashes
| Firefox Extension ID | Version | XPI SHA-256 |
|---|---|---|
view-focus-bright@webtools.co | 6.12.2 | 2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51 |
quick-track-nest@tabtools.co | 8.1.18 | 225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b |
vibe-kit-tool@fasttools.co | 9.21.9 | 6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8 |
edge-hub-snap@protools.net | 4.12.24 | 8906dd85b0991fac14e5973b3f3f61d93ef1101504cb5867a004c762ee184ef7 |
core-hub-peak@neattools.example | 8.24.21 | 9fea0ee3c81047f5e50eeb3a2ab2a7cd70357f3e49944b7079ab3e90c9ea0e8b |
sipoo-grozza@browserweb.com | 2.1 | 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35 |
mozart-seo@webtools.com | 1.4 | 635b31b4a19b5673fcbe0fedeb3f7ed2c27fddb739685f19ca5f3d1f1d7f0083 |
clean-file-bar@neattools.com | 4.21.8 | d9432e41e0401715bce4ce11f4a7104d94fab1ec89be553ba57a2097e418c1a1 |
clean-net-timer@plugify.example | 4.17.1 | 458e7255438f15aaede02fd7f8fcfdf762aa6e08608b9546fe8aa8aa399c76b7 |
manager-square@webtools.com | 1.4 | bb8f60b3f77d96adc93bf0515b34df7c5f1f560a9f6d0c353b7d849609e3557d |
manager-course@webtools.com | 1.4 | 71ec70479ab78efb1e1f9507f8ff7348d5711c837cc50a0120f3a188c340f3f4 |
val-andrew@browserweb.com | 1.4 | e96c75cd0c9b35000b4a3ec12d5dd23ca157e94aee7271a0fe8d8d7c9f2e9096 |
manager-team@browserweb.com | 1.4 | faf174414ddc7099360c4ae4d16497b9846cfae71ffad5bbab820bba657f94d3 |
valory-andrew@browserweb.com | 1.4 | b02ae1d5a0d2a5b28f8baa2afcdc7d7090fab051536303cba3ba1f17860da980 |
franklin-uk@browserweb.com | 1.4 | 4512389444a767f12211beeb5f2ad165aca4a558e88e8f111affb30b77ed6a5a |
franklin-uro@browserweb.com | 1.4 | e5c9a29d5ba0f53a49d8b333bfab17bf9878f94e8c3f325f5afacad44bb26fb5 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.