16 malicious Firefox extensions impersonated Rabby and OKX wallets

Firefox wallet impersonators targeted recovery phrases
Cybersecurity researchers identified 16 malicious Mozilla Firefox extensions that posed as Rabby Wallet and OKX Wallet products to steal cryptocurrency wallet recovery phrases and private keys. Socket researcher Joseph Edwards said the add-ons presented themselves as wallet portals, desktop utilities and browser tools, then intercepted secrets during wallet-import flows.
Four of the extensions were clones of Rabby Wallet, while the remainder targeted OKX Wallet. Their purpose was to collect mnemonic phrases and private keys and send them to attacker-controlled Cloudflare Workers infrastructure. Mozilla had removed all 16 extensions as of October 5, 2026.
Rotating identities, reused infrastructure
All but one of the identified extensions contacted the *.icy-star-f45c.workers[.]dev domain. Socket assessed the activity as a continuation of a wave it documented in August 2026.
The operators changed package names, versions, extension IDs, descriptions and the presentation layer. At the same time, they reused the wallet interfaces, credential-handling logic and network infrastructure. This combination allowed the campaign to alter its visible identity without changing the components used to capture and exfiltrate wallet credentials.
The extensions included names such as view-focus-bright@webtools.co, quick-track-nest@tabtools.co, vibe-kit-tool@fasttools.co and sipoo-grozza@browserweb.com. The misleading names underline that an extension’s branding or store description is not sufficient evidence that it is a legitimate wallet tool.
What affected users and organizations should do
Anyone who installed one of the extensions and entered a real recovery phrase or private key should assume that secret has been exposed. Socket recommends creating a new wallet from a clean system and moving assets to it. A recovery phrase or private key is sufficient to control the associated wallet, so deleting the extension alone does not remove the risk.
The findings arrive amid other reports of malicious or questionable extensions across Firefox, Google Chrome and Microsoft Edge, including add-ons that inject scripts, collect browsing data, redirect tabs or retrieve remote instructions. Browser extensions can obtain broad access to browser activity, making their permissions and runtime behaviour important security considerations.
For businesses, the practical response is to review installed browser extensions, remove those no longer needed and audit extensions in managed environments. Runtime monitoring and behaviour-based extension monitoring can help identify suspicious network activity and credential collection before it affects users or digital assets.

