Malware · 2h ago
Socket found 16 malicious Firefox extensions that copied Rabby and OKX wallet screens and stole recovery phrases and private keys during import flows. The campaign was built to look like ordinary wallet setup, not an obvious pop-up, and Mozilla has since unpublished the extensions.
The trick is simple: when a user imports a seed phrase or private key, the fake extension captures that secret and sends it out through Cloudflare Workers in the background. Several clones reuse the same lure, package patterns, and network path, so trusting the apparent publisher name or removing one add-on does not break the family.
For anyone allowing Firefox extensions on managed machines, the exposure sits at wallet-import time: the extension itself can be the thief, and once a real recovery phrase is entered, the wallet is effectively compromised outside the browser profile.
2 sources covering this story
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Sixteen malicious Firefox extensions imitate Rabby and OKX wallets to intercept recovery phrases and private keys during wallet imports.
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
Part of the PlainSec briefing for 2026-10-08