
16 Malicious Firefox Extensions Target Rabby and OKX Crypto Wallet Users
Security researchers uncovered 16 malicious Firefox extensions masquerading as ordinary tools that secretly clone Rabby and OKX crypto wallets to steal recovery phrases and private keys.
Malicious Extensions Disguised as Everyday Tools
Security researchers at Socket Threat Research have identified 16 malicious Firefox extensions targeting users of two popular cryptocurrency wallets, Rabby and OKX. Rabby is an Ethereum wallet and OKX is a DeFi wallet, each downloaded by more than a million users. The extensions initially present themselves as ordinary, unrelated tools, but hidden inside the malware are fake clones of real crypto wallets designed to intercept sensitive credentials.
Recovery Phrases Sent to Attacker-Controlled Servers
According to the report, the extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers. Victims are prompted to import their wallets, exposing their 12 or 24-word recovery phrases or private keys. Notably, every extension declared in its manifest that it collects no data at all, tricking users into believing they were safe.
Mozilla Removes Add-Ons, but Campaign Continues
Mozilla unpublished the malicious extensions from its add-ons store as of October 5, 2026. However, researchers warn that the campaign operators are unlikely to stop, as they frequently rotate package names, versions, IDs, descriptions, and overall presentation. Socket describes the discovery as a continuation of a previously reported crypto-theft campaign that planted at least 77 malicious Firefox extensions in August 2026. In an earlier incident, thousands of Firefox users were compromised by malware hidden inside extension icons.
What Affected Users Should Do
Researchers warn that any user who entered a recovery phrase or private key while these extensions were active should treat the wallet as compromised. Affected users are advised to immediately migrate to a new wallet created in a clean environment, protected by a new recovery phrase.
Sources: Cybernews
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.