Back
16 Malicious Firefox Extensions Target Rabby and OKX Crypto Wallet Users
SiTech AI Team2 min read

16 Malicious Firefox Extensions Target Rabby and OKX Crypto Wallet Users

Security researchers uncovered 16 malicious Firefox extensions masquerading as ordinary tools that secretly clone Rabby and OKX crypto wallets to steal recovery phrases and private keys.

Malicious Extensions Disguised as Everyday Tools

Security researchers at Socket Threat Research have identified 16 malicious Firefox extensions targeting users of two popular cryptocurrency wallets, Rabby and OKX. Rabby is an Ethereum wallet and OKX is a DeFi wallet, each downloaded by more than a million users. The extensions initially present themselves as ordinary, unrelated tools, but hidden inside the malware are fake clones of real crypto wallets designed to intercept sensitive credentials.

Recovery Phrases Sent to Attacker-Controlled Servers

According to the report, the extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers. Victims are prompted to import their wallets, exposing their 12 or 24-word recovery phrases or private keys. Notably, every extension declared in its manifest that it collects no data at all, tricking users into believing they were safe.

Mozilla Removes Add-Ons, but Campaign Continues

Mozilla unpublished the malicious extensions from its add-ons store as of October 5, 2026. However, researchers warn that the campaign operators are unlikely to stop, as they frequently rotate package names, versions, IDs, descriptions, and overall presentation. Socket describes the discovery as a continuation of a previously reported crypto-theft campaign that planted at least 77 malicious Firefox extensions in August 2026. In an earlier incident, thousands of Firefox users were compromised by malware hidden inside extension icons.

What Affected Users Should Do

Researchers warn that any user who entered a recovery phrase or private key while these extensions were active should treat the wallet as compromised. Affected users are advised to immediately migrate to a new wallet created in a clean environment, protected by a new recovery phrase.

Sources: Cybernews

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.