Mozilla Firefox users were recently targeted by a set of 16 malicious browser extensions that impersonated well-known crypto wallets or tools to steal recovery phrases and private keys. These add-ons, which mimicked Rabby Wallet and OKX Wallet, embedded hidden code that collected users’ sensitive credentials and sent them to a server controlled by threat actors.
The malicious extensions masqueraded as wallet portals, desktop utilities, and browser tools. During the wallet import process, they intercepted recovery phrases and private keys, routing them to attacker infrastructure hosted via Cloudflare Workers. Four of these extensions were fake Rabby Wallet clones; the remaining twelve imitated OKX Wallet. All of them—except one—communicated with a domain under *.icy-star-f45c.workers.dev to exfiltrate stolen credentials.
How the Scheme Worked & Detection Timeline
Researchers found that while the extensions changed superficial traits like names, versions, and descriptions, they reused internal wallet interfaces and core logic for credential handling. This suggests they’re part of a broader, evolving campaign that maintains stable backend infrastructure while rotating front-facing elements to bypass detection.
The campaign appears to extend work documented in August 2026, showing continued refinement of tactics. All 16 extensions were removed from Firefox’s ecosystem by October 5, 2026. But for anyone who installed one of these and entered real wallet recovery phrases or private keys, the compromise is assumed—recreating wallets from a clean environment and moving assets is now essential.
Other Browser Extension Threats & Defense Advice
This isn’t an isolated case. Malicious or suspicious extensions have recently been found across Firefox, Chrome, and Edge. The threats range from utilities that inject JavaScript into login pages, to tools that monitor users’ browsing, stash session cookies, or redirect users to phishing sites pretending to be wallet services. These campaigns often leverage common tactics—presenting as legitimate tools, using remote command servers, or impersonating recognizable crypto brands.
To protect yourself, audit every extension installed in your browser. Remove anything you’re not actively using. If you manage browser environments at scale, implement behavior-based extension monitoring and run regular audits. Watching for unusual network requests—like to domains you don’t recognize—is another useful red flag. And if you suspect you’ve been caught by one of these malicious extensions, start fresh: use a clean system to generate a new wallet and transfer assets immediately.
Why this matters: crypto wallets depend entirely on recovery phrases and private keys. Once those are exposed, funds are as good as gone. These attacks underline how browser-based threats have adapted to target crypto users more directly. Going forward, changes in extension store review processes or stronger verification for crypto-related tools may be needed—and users should be extra cautious during installation or wallet import flows.