Cybersecurity researchers have uncovered a new cluster of 16 malicious Mozilla Firefox extensions specifically designed to target cryptocurrency users by stealing their wallet recovery phrases and private keys.

According to an analysis published by application security company Socket, these rogue browser add-ons masquerade as legitimate wallet portals, desktop utilities, and standard productivity tools. However, beneath their benign appearance lies malicious code engineered to covertly intercept recovery phrases and private keys during routine wallet import flows, subsequently exfiltrating these sensitive credentials to attacker-controlled Cloudflare Workers infrastructure.

Socket researcher Joseph Edwards detailed the mechanics of the threat, explaining how the extensions systematically trick users into revealing critical security secrets. Four of the identified extensions are direct clones of Rabby Wallet, while the remaining twelve function as targeted clones of OKX Wallet. Aside from a single outlier, virtually all of the malicious add-ons were found to communicate with the exact same domain, utilizing variations of the "*.icy-star-f45c.workers.dev" address format. The ultimate objective of this infrastructure is to harvest mnemonic phrases and private keys, funneling them directly back to the operators behind the campaign.

This newly uncovered activity has been assessed by security analysts as a direct continuation of an earlier, larger wave of attacks originally documented by Socket in August 2026, when a batch of roughly 40 malicious Firefox extensions was caught engaging in similar credential-theft tactics. The persistence of these campaigns indicates that the threat actors behind them are actively iterating on their deployment strategies. Rather than inventing entirely new methodologies, the perpetrators are continuously rotating package names, version numbers, unique extension IDs, descriptions, and user-facing presentation layers while reusing identical underlying wallet interfaces, credential-handling logic, and network infrastructure.

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

By slightly altering the cosmetic appearance and packaging of the extensions, the attackers attempt to evade automated detection systems and bypass manual review processes on official app stores, allowing them to persistently trick unsuspecting web browsers.

Swift action by platform administrators and security researchers led to the removal of all 16 extensions from the Mozilla ecosystem. However, because these add-ons were actively distributed and installed prior to their takedown, security professionals emphasize the severe risks facing anyone who interacted with them. Users who previously installed any of the flagged extensions and entered a real recovery phrase, mnemonic, or private key into the fake wallet interfaces are urged to treat their assets as fully compromised. Security guidelines dictate that impacted individuals must immediately generate a completely new cryptocurrency wallet from a clean, uncompromised system and transfer remaining digital assets to safety before the threat actors can drain them.

The discovery of these Firefox-targeted wallet stealers coincides with a broader, worrying trend observed across the cybersecurity landscape in recent months. Security analysts have cataloged a steady stream of malicious or highly suspicious extensions targeting not only Mozilla Firefox, but also other major web browsers including Google Chrome and Microsoft Edge. These multi-browser campaigns highlight a systemic challenge in the digital ecosystem, where browser extensions—often granted broad permissions to read and alter web page content—frequently serve as an attractive vehicle for threat actors looking to intercept sensitive user inputs, financial credentials, and authentication tokens.

In response to these persistent risks, cybersecurity experts strongly recommend that individual internet users regularly audit their browser environments and promptly uninstall any extensions that are no longer actively used or whose provenance cannot be definitively verified. Meanwhile, organizations and enterprise IT administrators are advised to implement stricter governance over browser environments within managed networks. Recommendations for corporate environments include conducting comprehensive audits of installed extensions, adopting runtime monitoring solutions, and deploying behavior-based extension monitoring technologies capable of identifying and blocking suspicious network traffic and unauthorized data exfiltration attempts before sensitive information leaves the local machine.

Leave a Reply

Your email address will not be published. Required fields are marked *