16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys during wallet imports.
Disguised as wallet portals, desktop utilities, and browser tools, the packages attempt to transmit secrets to attacker-controlled Cloudflare Workers.
Mozilla had unpublished the extensions by October 5, 2026, according to Socket’s October 7 report.
Fifteen packages contain active collection handlers; one ships with implementation defects that prevent its normal theft workflow.
Every manifest declares data collection permission “none,” contradicting the packaged credential-transmission code.
The Rabby clones use the deceptive branding “Raabby WaIIet” and contain 1,114 files each, including wallet keyrings, import screens, transaction interfaces, and Webpack components.
Their substantial legitimate functionality makes the malicious additions less conspicuous than a standalone phishing form. Official Rabby links and retained DeBank assets further reinforce the impersonation.
Inside background.js, an injected self._lv helper accepts 12-word or 24-word recovery phrases and 64-character hexadecimal private keys.
Attackers inserted calls after operations including importPrivateKey and createKeyringWithMnemonics, capturing the same secrets accepted by the wallet while allowing legitimate processing to continue.
Additional hooks in 977.js collect secrets from frontend import paths.
Socket Researchers identified that, the campaign comprises four modified Rabby Wallet applications and twelve compact extensions using OKX-derived interfaces.
The stolen values travel in HTTPS GET parameters to silent-wind-get.icy-star-f45c[.]workers[.]dev.
Every manifest declares Firefox collection permission none, contradicting the code that handles and transmits wallet recovery material.
Requests include the raw secret in w, campaign marker EQOx7EIPZSNi, and an action identifying frontend or background collection.
Failed fetch requests trigger an XMLHttpRequest fallback. Putting secrets in URLs also risks exposing them through request logging.
The smaller extensions present “Portal WALLET” onboarding screens with OKX-style components and official OKX help links.
Their React frontend validates exactly 12 or 24 words before dispatching SEED_PHRASE_IMPORT with the entered phrase.
Active background handlers accept that message and the legacy alias WALLET_SYNC, then transmit the unencrypted phrase inside an HTTPS request.
Most use POST JSON containing fields a, s, k, and w. Another packaged handler implements navigator.sendBeacon, a fetch POST, and an image-pixel GET fallback.
Although comments claim only a hash and word count leave the device, the payload explicitly includes the raw phrase; hashing serves only deduplication.
The defective sipoo-grozza@browserweb.com version 2.1 lacks a manifest declaration loading background.js. Its frontend and packaged handler also disagree on message types.
Socket therefore distinguishes malicious intent from operational capability rather than counting this sample as successfully exfiltrating through its normal workflow.
Shared code, Worker infrastructure, and the campaign marker connect these packages to Socket’s August investigation, which tracked 77 related extensions: 40 confirmed malicious and 37 deceptive sports-score shells.
Socket assesses the latest operation as a continuation with high confidence, without establishing a named operator.
Defenders can consult the report’s extension inventory and indicators, hunt for shared hashes and markers, and block identified Worker endpoints.
Telemetry should redact w to avoid duplicating stolen secrets. Legitimate Rabby and DeBank domains are not campaign indicators; broad permissions alone do not establish additional browsing-data theft.
Users who submitted secrets should treat affected wallets as compromised, remove the extensions, create fresh wallets from a clean environment, and transfer assets immediately.
Changing an extension password cannot invalidate an exposed recovery phrase or private key.
| Category | Indicator |
|---|---|
| Campaign code marker | EQOx7EIPZSNi |
| Campaign code marker | Raabby WaIIet |
| Campaign code marker | SEED_PHRASE_IMPORT |
| Campaign code marker | WALLET_SYNC |
| Network indicator | hxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/ |
| Network indicator | hxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/ |
| Network indicator | hxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/ |
| Network indicator | hxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/ |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…