Two Windows stealers and 16 fake Firefox wallet extensions
K7 and Microsoft detailed separate Windows credential stealers, while 16 fake Rabby and OKX Firefox extensions stole wallet secrets before Mozilla removed them.
K7 Security Labs analyzed TokenGrabberBuilder.zip, a nested-archive Python infostealer builder whose Windows payloads harvest browser secrets, cards, cookies, Discord tokens, Roblox cookies, and plaintext Wi-Fi passwords, then post an in-memory StolenData zip to a webhook while persisting through a deceptive WindowsUpdate Run key and an ONLOGON task. Separately, Microsoft Threat Intelligence described ClickFix pages that use fake CAPTCHA prompts and a cache-as-PNG trick so users launch a VBScript, after which PowerShell stages load in-memory .NET payloads that steal browser credentials, inject code into timeout.exe, and persist via a per-user PowerShell Bypass policy and a Python scheduled task. In a third thread, Socket found 16 Firefox add-ons—four Rabby clones and 12 OKX-style fakes—that hook wallet import to steal recovery phrases and private keys and send them to Cloudflare Workers; Mozilla unpublished all 16 by October 5, 2026. Accounts agree on that count, date, and an August campaign tied to marker EQOx7EIPZSNi, but differ in detail: GBHackers reports 15 working packages, one defective add-on, the brand 'Raabby WaIIet,' and a high-confidence link to 77 related extensions, while The Hacker News stresses rotating names and IDs and separate browser clusters, and Cyber Security News says Rabby clones used GET URLs whereas OKX-style handlers used HTTPS POST. The Hacker News also describes other Firefox, Chrome, and Edge clusters that steal Google session cookies, phish wallets, proxy traffic, and harvest AI chats, and reporters advise anyone who entered a real seed phrase to abandon that wallet.
- K7 Security Labs analyzed TokenGrabberBuilder.zip, a Python builder that emits Windows payloads via Nuitka, PyInstaller, or raw Python; stealer.py takes passwords, cards, history, and cookies from at least 17 Chromium browsers plus…
- Microsoft Threat Intelligence reported ClickFix lures: fake CAPTCHA pages prefetch a script into the browser cache disguised as a PNG, a pasted Run command launches it as VBScript via wscript.exe, and later in-memory .NET stages steal…
- Socket identified 16 malicious Firefox extensions—four Rabby Wallet clones (GBHackers: branded 'Raabby WaIIet'; Cyber Security News: the larger packages) and 12 OKX-style fakes—that capture 12- or 24-word recovery phrases and private keys,…
- Mozilla had removed all 16 listings by October 5, 2026; exfiltration went to Cloudflare Workers, including silent-wind-get.icy-star-f45c.workers.dev, with campaign marker EQOx7EIPZSNi.
- Sources disagree on scope: GBHackers says 15 handlers worked and one was defective and cites a high-confidence link to an August operation tracking 77 extensions; The Hacker News describes an August 2026 wave that rotates names and IDs;…
- The Hacker News also describes separate Firefox, Chrome, and Edge clusters that steal Google session cookies, redirect users to wallet-phishing pages, proxy traffic, and harvest AI chatbot conversations.
- Users who submitted real seed phrases should treat those wallets as compromised, create a new wallet, and move assets from a clean environment.
Coverage timelineoldest first · each row is one article
- · 6d agoNew Infostealer Can Steal Passwords, Cards, Cookies and Wi-Fi Keys From Windows PCs
GBHackers· 48
K7 Labs analyzed a Python infostealer builder that steals Windows browser secrets, cards, cookies, Discord tokens, and Wi-Fi passwords.
- · 5d agoMicrosoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands
GBHackers· 74
Microsoft warns a ClickFix campaign uses fake CAPTCHA prompts so Windows users run cached malware that steals browser credentials.
- · 14h ago