Cyber Security News

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys during wallet imports.

Disguised as wallet portals, desktop utilities, and browser tools, the packages attempt to transmit secrets to attacker-controlled Cloudflare Workers.

Mozilla had unpublished the extensions by October 5, 2026, according to Socket’s October 7 report.

Fifteen packages contain active collection handlers; one ships with implementation defects that prevent its normal theft workflow.

Every manifest declares data collection permission “none,” contradicting the packaged credential-transmission code.

The Rabby clones use the deceptive branding “Raabby WaIIet” and contain 1,114 files each, including wallet keyrings, import screens, transaction interfaces, and Webpack components.

Their substantial legitimate functionality makes the malicious additions less conspicuous than a standalone phishing form. Official Rabby links and retained DeBank assets further reinforce the impersonation.

Inside background.js, an injected self._lv helper accepts 12-word or 24-word recovery phrases and 64-character hexadecimal private keys.

Attackers inserted calls after operations including importPrivateKey and createKeyringWithMnemonics, capturing the same secrets accepted by the wallet while allowing legitimate processing to continue.

Additional hooks in 977.js collect secrets from frontend import paths.

Rabby Clone Interface (Source : Socket).

Socket Researchers identified that, the campaign comprises four modified Rabby Wallet applications and twelve compact extensions using OKX-derived interfaces.

16 Malicious Firefox Extensions

The stolen values travel in HTTPS GET parameters to silent-wind-get.icy-star-f45c[.]workers[.]dev.

Every manifest declares Firefox collection permission none, contradicting the code that handles and transmits wallet recovery material.

Requests include the raw secret in w, campaign marker EQOx7EIPZSNi, and an action identifying frontend or background collection.

Failed fetch requests trigger an XMLHttpRequest fallback. Putting secrets in URLs also risks exposing them through request logging.

Fake Wallet Interface (Source : Socket).

The smaller extensions present “Portal WALLET” onboarding screens with OKX-style components and official OKX help links.

Their React frontend validates exactly 12 or 24 words before dispatching SEED_PHRASE_IMPORT with the entered phrase.

Active background handlers accept that message and the legacy alias WALLET_SYNC, then transmit the unencrypted phrase inside an HTTPS request.

Most use POST JSON containing fields a, s, k, and w. Another packaged handler implements navigator.sendBeacon, a fetch POST, and an image-pixel GET fallback.

Although comments claim only a hash and word count leave the device, the payload explicitly includes the raw phrase; hashing serves only deduplication.

The defective sipoo-grozza@browserweb.com version 2.1 lacks a manifest declaration loading background.js. Its frontend and packaged handler also disagree on message types.

Socket therefore distinguishes malicious intent from operational capability rather than counting this sample as successfully exfiltrating through its normal workflow.

Shared code, Worker infrastructure, and the campaign marker connect these packages to Socket’s August investigation, which tracked 77 related extensions: 40 confirmed malicious and 37 deceptive sports-score shells.

Socket assesses the latest operation as a continuation with high confidence, without establishing a named operator.

Defenders can consult the report’s extension inventory and indicators, hunt for shared hashes and markers, and block identified Worker endpoints.

Telemetry should redact w to avoid duplicating stolen secrets. Legitimate Rabby and DeBank domains are not campaign indicators; broad permissions alone do not establish additional browsing-data theft.

Users who submitted secrets should treat affected wallets as compromised, remove the extensions, create fresh wallets from a clean environment, and transfer assets immediately.

Changing an extension password cannot invalidate an exposed recovery phrase or private key.

IOCs

CategoryIndicator
Campaign code markerEQOx7EIPZSNi
Campaign code markerRaabby WaIIet
Campaign code markerSEED_PHRASE_IMPORT
Campaign code markerWALLET_SYNC
Network indicatorhxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/
Network indicatorhxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/
Network indicatorhxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/
Network indicatorhxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

3 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

3 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

5 hours ago

wolfSSH Patches 5 Security Vulnerabilities, Including Critical SSH Authentication Bypass

wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…

5 hours ago