Breaking
Cyber CrimeDeveloping Story

Fake Firefox Wallets Target Recovery Phrases

Sixteen malicious Firefox extensions cloned Rabby and OKX wallet interfaces to intercept recovery phrases and private keys, researchers say.

··2 hours ago·7 min read
a close up of a bunch of gold coins
Photo by rc.xyz NFT gallery on Unsplash

Sixteen malicious Mozilla Firefox extensions have been found masquerading as cryptocurrency wallet portals, desktop utilities, and browser tools — and their code is built to intercept wallet recovery phrases and private keys during import flows, according to an analysis by application security firm Socket.

The extensions present themselves as legitimate wallet interfaces, but the credentials entered into them are routed to infrastructure controlled by the attackers, the company reported. All of the identified add-ons barring one were found to contact the *.icy-star-f45c.workers[.]dev domain, a Cloudflare Workers endpoint used as the exfiltration destination.

Socket published its findings on October 8, 2026, describing the campaign as a continuation of activity it documented earlier in the same year.

Clones of Rabby and OKX

Four of the sixteen extensions are clones of Rabby Wallet, while the remaining twelve are targeted clones of OKX Wallet, according to Socket. The add-ons were distributed under names and identifiers that imitate ordinary browser tooling rather than wallet software, which is how they appear in an extension list.

The full set of extension identifiers Socket listed is:

  • view-focus-bright@webtools.co@6.12.2
  • quick-track-nest@tabtools.co@8.1.18
  • vibe-kit-tool@fasttools.co@9.21.9
  • edge-hub-snap@protools.net@4.12.24
  • core-hub-peak@neattools.example@8.24.21
  • sipoo-grozza@browserweb.com@2.1
  • mozart-seo@webtools.com@1.4
  • clean-file-bar@neattools.com@4.21.8
  • clean-net-timer@plugify.example@4.17.1
  • manager-square@webtools.com@1.4
  • manager-course@webtools.com@1.4
  • val-andrew@browserweb.com@1.4
  • manager-team@browserweb.com@1.4
  • valory-andrew@browserweb.com@1.4
  • franklin-uk@browserweb.com@1.4
  • franklin-uro@browserweb.com@1.4

Socket did not say how many users installed the extensions or how much cryptocurrency may have been taken. The company's analysis focused on what the extension code does once a user interacts with the fake wallet interface.

How the credential theft works

According to Socket, the extensions intercept recovery phrases and private keys at the point where a user imports an existing wallet. That import flow is precisely where a wallet asks for the seed phrase or private key that controls funds, which makes it the highest-value target in any wallet compromise.

The extension code then attempts to send the captured secrets to attacker-controlled Cloudflare Workers, the company said. The use of a Cloudflare Workers subdomain gives the exfiltration traffic a plausible-looking destination that blends in with ordinary web requests, and it lets the operators change collection infrastructure without pushing a new extension version to victims.

"The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers."

— Joseph Edwards, Socket researcher

Once a recovery phrase or private key leaves a device, the attacker can reconstruct the wallet and move any funds the wallet controls. There is no password reset for a seed phrase; possession of the phrase is possession of the funds.

What the new wave changed

Socket assessed the activity as part of the same campaign it documented in August 2026. In the earlier wave, the operators used a different set of extension names, versions, and identifiers while keeping the same underlying approach.

Between the two sets of findings, the attackers rotated package names, versions, extension IDs, descriptions, and the presentation layer, according to Socket. What stayed the same, the company said, were the wallet interfaces, the credential-handling logic, and the network infrastructure — meaning the operators are rebuilding the storefront around the same collection machinery.

That pattern matters for detection. Blocking a single extension ID or a single version number catches only the specific artifacts that have already been reported. A defender who instead looks for the behavior — an extension that reads seed-phrase input fields and posts them outward — has a better chance of catching the next rotation.

Removal and what exposed users should do

As of October 5, 2026, all of the extensions have been removed, according to Socket. Removal from the add-on store stops new installs, but it does not remove software from browsers where it was already installed.

Socket's guidance for anyone who installed any of the listed extensions and entered a real recovery phrase or private key into the fake wallet interfaces is direct: assume compromise, create a new wallet from a clean system, and move assets to it. The reasoning is that a recovery phrase typed into an attacker-controlled interface should be treated as disclosed, even if no funds have moved yet.

The safe order of operations matters here. Generating the replacement wallet on a machine that may still be running the malicious extension risks exposing the new phrase in turn, which is why the clean-system step comes before the new wallet is created.

The broader malicious-extension pattern

The Firefox findings arrived alongside a series of other discoveries involving malicious or questionable extensions for Firefox, Google Chrome, and Microsoft Edge, according to the source coverage.

Those include a Firefox extension called "ID- Pay" (pdf-para-texto@extensao.local) that poses as a utility for verifying identity before opening protected PDF documents, but carries functionality to fetch a remote payload from attacker-controlled infrastructure and inject JavaScript into the legitimate "accounts.google[.]com" domain to steal session cookies.

They also include a cluster of 32 malicious browser extensions across the Chrome Web Store and Microsoft Edge Add-ons Store that masquerade as benign productivity utilities while harvesting data, monitoring browsing habits, and stealthily replacing the active tab with a destination URL specified in a remotely retrieved configuration. That campaign has been active since March 2025 and is attributed to a Korean-speaking threat actor.

A further cluster of about 30 malicious browser extensions masquerades as productivity tools, privacy utilities, and cryptocurrency-related services published under the names of legitimate, high-profile financial personalities. Their goal is to redirect victims to cryptocurrency wallet phishing pages designed to steal recovery phrases, while skipping English-speaking users and analysis environments.

Separately, a cluster of 31 Russian-language Chrome extensions advertised as VPNs for a specific blocked service in the country — including Anthropic Claude, Facebook, Google Gemini, LinkedIn, Netflix, Notion, OpenAI ChatGPT, Spotify, Telegram, Threads, Wikipedia, X, and YouTube — routes browser traffic through a proxy whose server list is fetched from a GitHub Pages URL after installation, with Blogger, Google Docs, and Telegram used for redundancy.

Data collection beyond wallet theft

Not every extension in the wider set targets cryptocurrency. A Chrome Web Store extension named Stylish intercepts every ChatGPT, Gemini, Claude, Perplexity, Character.AI, and GitHub Copilot conversation and forwards the full response text to its operator, according to the coverage.

A Chrome Web Store extension named "Urban VPN" includes an "anti-phishing" feature designed to warn users before visiting harmful sites, but never returns a phishing warning and silently transmits visited URLs to servers operated by BIScience. Urban VPN was previously accused of capturing user conversations with AI chatbots; the extension developers clarified that AI-related processing only occurs after the "AI Protection" feature was explicitly enabled. Earlier in May, the add-on developers also addressed a high-severity security vulnerability that allowed any website to send arbitrary commands to the extension without origin verification.

Another Chrome Web Store extension, "Pop up blocker for Chrome™ - Poper Blocker," is marketed as an ad blocker but ships an interpreter that downloads and interprets instructions from a command-and-control server, circumventing Google's Manifest V3 rules banning this behavior. The commands allow it to collect browser fingerprints, browsing history, social media profile information, and AI chatbot interactions.

Taken together, the cases show that an extension's stated purpose is a weak signal of what it actually does. The permissions an extension requests, the network destinations it contacts, and whether its code changes after installation are more useful indicators.

Auditing what is installed

The guidance that accompanies these findings is consistent: review the browser extensions installed in your environment and remove the ones that are no longer needed.

For organizations, the recommendations go further. Auditing extensions within managed environments, adopting runtime monitoring approaches, and deploying behavior-based extension monitoring technologies are the suggested measures for detecting suspicious activity. Runtime and behavior-based approaches are aimed at catching malicious activity that static review or store-level vetting misses, including extensions that fetch their instructions or destinations after installation.

The practical difficulty is scale. Extensions accumulate over years, are installed by individual employees without central visibility in many environments, and often retain broad permissions long after the task they were installed for is done. The Firefox cluster shows what an extension can do with a permission set that looks unremarkable at install time.

Why this matters

For anyone holding cryptocurrency in a browser-accessible wallet, the recovery phrase remains the single point of failure — and it is the exact input the Firefox cluster was built to capture. Socket's advice to treat any phrase entered into one of the listed fake interfaces as compromised is the conservative reading, and it is the right one: the cost of migrating to a freshly generated wallet is far lower than the cost of discovering the problem after funds move.

The broader extension cases suggest that store review alone is not a reliable filter. That puts more of the burden on users and IT teams to know what is installed, to remove extensions that are no longer in use, and to treat wallet import prompts with the same suspicion as any other request for a secret. For businesses, managed-environment auditing and behavior-based monitoring are the controls that match how these campaigns actually operate — by changing their names and versions while reusing the same collection logic underneath.

#browser extensions#cryptocurrency#malware#firefox#wallet phishing#credential theft

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories