Malware & Tooling · Credential Theft

16 Firefox Extensions Impersonate Wallets to Steal Seeds

Socket found 16 malicious Firefox extensions that copied Rabby and OKX wallet screens and stole recovery phrases and private keys during import flows. The campaign was built to look like ordinary wallet setup, not an obvious pop-up, and Mozilla has since unpublished the extensions.

The trick is simple: when a user imports a seed phrase or private key, the fake extension captures that secret and sends it out through Cloudflare Workers in the background. Several clones reuse the same lure, package patterns, and network path, so trusting the apparent publisher name or removing one add-on does not break the family.

For anyone allowing Firefox extensions on managed machines, the exposure sits at wallet-import time: the extension itself can be the thief, and once a real recovery phrase is entered, the wallet is effectively compromised outside the browser profile.

2 sources · 3h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: 16 Firefox Extensions Impersonate Wallets to Steal Seeds