Back Socket.Dev 16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
Socket Threat Research identified a coordinated campaign of 16 Firefox extensions targeting cryptocurrency wallet users. The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers.
The campaign is a cryptocurrency wallet credential-stealing operation with a variety of lures:
Four large extensions are clones of Rabby Wallet, a popular Ethereum wallet app with 900,000 users on the Chrome Web Store and 500,000 downloads on Google Play. They impersonate Rabby as Raabby WaIIet , hook mnemonic and private-key import paths, and send the raw secret to a Cloudflare Worker using GET query parameters.
Twelve smaller extensions are targeted clones of OKX Wallet, the popular DeFi wallet app with over 1,000,000 users on then Chrome Web Store. Eleven register a background script that receives a 12- or 24-word phrase and sends it to a Cloudflare Worker. One, [email protected] , packages exfiltration code but is broken as shipped: its manifest does not load background.js , and its frontend sends SEED_PHRASE_IMPORT while the packaged background handles only WALLET_SYNC .
Fifteen of the extensions icy-star-f45c[.]workers[.]dev ; the broken variant uses fondationanimalaidrelief[.]workers[.]dev but retains the same frontend and campaign marker.
Every manifest declares Firefox data collection permission none , contradicting the code that handles and transmits wallet recovery material.
The operators rotate package names, versions, extension IDs, descriptions, and presentation while reusing the same wallet interfaces, credential-handling logic, campaign marker, and network infrastructure. This reuse separates the extensions into a large Rabby wallet clone family and a OKX wallet-phishing family with three background-script variants. Due to reused infrastructure, tactics and targeted lures, we assess with high confidence that this campaign is a continuation of crypto-theft targeted extensions Socket identified in August 2026.
Note : As of October 5th, Mozilla has unpublished the malicious extensions. Any user who entered a real recovery phrase or private key into any functioning variant should treat the wallet as compromised: create a new wallet from a clean environment and move assets immediately. Changing only the extension password does not revoke a stolen seed phrase or private key.
Affected Extensions #
[email protected]@6.12.2
[email protected]@8.1.18
[email protected]@9.21.9
[email protected]@4.12.24
[email protected]@8.24.21
[email protected]@4.21.8
[email protected]@4.17.1
Installation and Presentation #
The four large packages are repackaged wallet applications rather than small utility extensions. Each contains 1,114 files and a Webpack application with webpackChunkrabby , Rabby locale material, wallet keyring code, import screens, and transaction UI.
The branding is altered to Raabby WaIIet , including index.html , desktop.html , locale names, document titles, and selected application strings. This misspelling is consistent across the otherwise Rabby-derived application and provides a useful static detection string.
Brand and Infrastructure Inheritance #
The rebranding is incomplete in ways that strengthen the impersonation finding. The rendered onboarding screen says “Rabby Wallet,” the document title says Raabby WaIIet, and the manifest identifies the author as Debrunk. The application also preserves links to Rabby’s official Chrome Web Store listing, Rabby legal pages, and Rabby mobile applications in the Apple App Store and Google Play.
The clone retains upstream Rabby and DeBank service configuration, including api.rabby.io , download.rabby.io , static-assets.rabby.io , static.debank.com , static-assets.debank.com , and matomo.debank.com . During isolated rendering, the application attempted to load an image from static-assets.debank.com and send page-view telemetry to matomo.debank.com ; both requests were blocked before . The packaged Matomo client uses site ID 2 and derives its visitor identifier from the extension ID.
These connections show that the operators repackaged a substantial Rabby codebase and left its upstream assets, service URLs, and analytics intact while injecting a separate credential-theft channel. The Rabby and DeBank hosts are not campaign IOCs and should not be blocked solely because they occur in these packages.
The manifests are Firefox Manifest V2 and expose unusually broad capability:
persistent background.html page;
content script at document_start in all frames;
matches file://*/* , , and ;
webRequest and webRequestBlocking ;
arbitrary HTTP and HTTPS host access;
explicit access to the malicious Worker endpoint;
unsafe-eval and WebAssembly evaluation in the CSP;
storage, unlimited storage, active tab, context , and notification permissions.
The content-script breadth is greater than required for the observed wallet-secret exfiltration. Static analysis did not identify a separate form-grabber claim, so the risk should be described as excessive access rather than unproven browsing-data theft.
The compact extensions impersonate a generic wallet portal, but the logo and presentation closely resemble OKX Wallet. Their shared index.html is titled Portal WALLET ; the React frontend presents a recovery-phrase import workflow, validates exactly 12 or 24 words, and sends this browser-runtime message:
Eleven manifests register background.js and expose a browser-action icon titled Open My Window . Clicking it causes the background script to open index.html in a 400x664 popup window.
Fake Wallet Interface #
The shared compact frontend uses polished wallet branding and a familiar onboarding flow to direct victims toward credential entry:
Rabby-Clone Background Hooks #
At the start of background.js , the malware installs self._lv . This function accepts only:
a 64-character hexadecimal string consistent with a raw private key.
The function deduplicates values in memory, URL-encodes the raw secret, and sends it to the Worker. Calls to self._lv were inserted directly after legitimate-looking wallet operations, including:
createKeyringWithMnemonics ;
mnemonic keyring/account import paths.
This placement gives the attacker the same secret the wallet accepts, while leaving the underlying wallet flow intact.
Rabby-Clone UI Hooks #
977.js defines a second exfiltration helper and includes inline copies at UI import paths. Confirmed call sites transmit:
the mnemonic passed to generateKeyringWithMnemonic ;
the seed phrase entered during new-user import;
the private key entered during private-key import;
the seed phrase used during password-protected keyring creation.
The UI helper tags requests with action ui ; the background helper uses action import . Multiple hooks improve collection coverage and can generate more than one network request for the same user secret.
The shared frontend responsible for phishing a user’s seed phrase passes { seedPhrase } to SEED_PHRASE_IMPORT . The active background variants accept SEED_PHRASE_IMPORT and the legacy alias WALLET_SYNC , trim the secret, reject empty input, require exactly 12 or 24 words, and deduplicate the raw phrase in memory.
The resulting request contains the phrase verbatim in field w . For the Web3 Portal family the body is:
The core variant sends the same four fields to a different Worker host. Its background is minified but functionally equivalent.
Secret Exfiltration #
Rabby-Clone Transport #
The large family sends a GET request with mode: "no-cors" and keepalive: true . If fetch rejects, it retries with XMLHttpRequest . The request format is:
Using a GET query exposes the secret not only to the Worker but also to infrastructure request logs, URL logging, and any intermediary that records request targets.
OKX-Clone Transport #
The OKX Web3 Portal variants send the raw phrase via HTTPS POST JSON. Their background logic attempts to read the response and report success to the UI.
One extension contained a background script using a more resilient, write-only sequence:
navigator.sendBeacon with URL-encoded form data;
fetch POST with mode: "no-cors" and keepalive ;
an image-pixel GET fallback.
Its claim only a hash and word count leave the device, but the payload explicitly assigns the raw phrase to parameter w . The FNV-1a value is used only for deduplication. This /code contradiction is direct evidence of concealment rather than benign analytics.
[email protected]@2.1 is not operational through its normal packaged flow for two independent reasons:
manifest.json contains no background declaration, so Firefox does not load background.js .
The shared frontend emits SEED_PHRASE_IMPORT , while the background routes only WALLET_SYNC .
Its browser action has no default popup. The packaged background.js would have registered the click listener that opens index.html , but that script is never loaded. index.html remains web-accessible, yet manually opening it still does not activate the absent/mismatched handler.
This is a delivery defect, not evidence of benign intent. The packaged code still contains explicit raw-secret collection, a remote destination, and three exfiltration transports. A repaired manifest and event case would make it functional.
Campaign Attribution #
The extensions separate into two closely related implementation groups:
Rabby clone — four extensions: All 1,108 non-manifest, non-signature files are identical. The extensions collect 12- or 24-word mnemonics and 64-hex private keys, then send them to silent-wind-get.icy-star-f45c.workers[.]dev . Their exfiltration hooks load normally, and the endpoint is covered by explicit host permission.
OKX Clone Web3 Portal — ten extensions: All 20 non-manifest, non-signature files are identical. These extensions collect 12- or 24-word mnemonics through green-firefly-ab28.icy-star-f45c[.]workers[.]dev , small-boat-969c.icy-star-f45c[.]workers[.]dev or flat-wildflower-f954.fondationanimalaidrelief[.]workers[.]dev . Their handlers load, but their manifests omit the remote host.
Additional relationships directly observed:
One campaign marker EQOx7EIPZSNi appears in every family. This marker also surfaced in our research on this threat actor.
This marker also surfaced in our research on this threat actor.
Fifteen of the sixteen extensions the same login key and import action schema.
Fifteen of the sixteen extensions use three Worker names beneath the exact suffix icy-star-f45c[.]workers[.]dev .
All twelve OKX clone extensions an identical frontend and 19/20 non-metadata files.
Ten OKX clone samples have an identical 4,160-byte background.js .
The four Rabby clone samples have an identical background.js and application files outside manifest/signature metadata.
The compact package names, versions, extension IDs, and descriptions vary while payload code remains fixed.
These facts support builder pipeline with at least two generated campaign variants.
Detection Opportunities #
High-confidence static detections:
Fake brand string Raabby WaIIet ;
message types SEED_PHRASE_IMPORT and WALLET_SYNC adjacent to raw seedPhrase handling;
JSON fields a , s , k , w with values import , EQOx7EIPZSNi , login , and a 12/24-word phrase;
GET parameters w , s , k , a , and t sent to the Workers endpoint;
manifests declaring data_collection_permissions.required = ["none"] while code transmits wallet recovery material;
identical background.js hashes listed below.
Network detections should account for the secret-bearing query or body without logging the actual secret into additional security systems. Match host, path, method, parameter names, and campaign marker; redact field w .
Response Recommendations #
For an affected user:
Disconnect the system from wallet workflows and remove every listed extension ID.
From a clean device, create a new wallet with a new recovery phrase.
Transfer assets and revoke token approvals associated with the exposed wallet.
Treat every account derived from the exposed mnemonic as compromised.
Do not rely on changing the extension password; it does not invalidate the mnemonic or private key.
Review browser profiles and synchronized extension state on every Firefox device.
Block the listed extension IDs and XPI hashes.
extension inventories for the four background.js hashes and the campaign marker.
proxy/DNS telemetry for the three Worker namespaces, while preventing secret field w from being copied into case notes or alerts.
Preserve the original XPI and browser profile for incident scope, but never run the extension on an analyst host.
Hunt for other extension packages with the shared compact frontend hash or identical Rabby-derived file set.
Indicators of Compromise #
Campaign Code Markers #
hxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/
hxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/
hxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/
hxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/
Rabby-clone background.js SHA-256: 7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799
OKX Clone core background.js SHA-256: da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd
Broken variant background.js SHA-256: be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897
OKX Clone Web3 Portal background.js SHA-256: c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f
Shared compact frontend SHA-256: eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf
Extension IDs and XPI SHA-256 Hashes #
[email protected] , version 6.12.2 — 2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51
[email protected] , version 8.1.18 — 225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b
[email protected] , version 9.21.9 — 6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8
[email protected] , version 4.12.24 — 8906dd85b0991fac14e5973b3f3f61d93ef1101504cb5867a004c762ee184ef7
[email protected] , version 8.24.21 — 9fea0ee3c81047f5e50eeb3a2ab2a7cd70357f3e49944b7079ab3e90c9ea0e8b
[email protected] , version 2.1 — 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35
[email protected] , version 1.4 — 635b31b4a19b5673fcbe0fedeb3f7ed2c27fddb739685f19ca5f3d1f1d7f0083
[email protected] , version 4.21.8 — d9432e41e0401715bce4ce11f4a7104d94fab1ec89be553ba57a2097e418c1a1
[email protected] , version 4.17.1 — 458e7255438f15aaede02fd7f8fcfdf762aa6e08608b9546fe8aa8aa399c76b7
[email protected] , version 1.4 — bb8f60b3f77d96adc93bf0515b34df7c5f1f560a9f6d0c353b7d849609e3557d
[email protected] , version 1.4 — 71ec70479ab78efb1e1f9507f8ff7348d5711c837cc50a0120f3a188c340f3f4
[email protected] , version 1.4 — e96c75cd0c9b35000b4a3ec12d5dd23ca157e94aee7271a0fe8d8d7c9f2e9096
[email protected] , version 1.4 — faf174414ddc7099360c4ae4d16497b9846cfae71ffad5bbab820bba657f94d3
[email protected] , version 1.4 — b02ae1d5a0d2a5b28f8baa2afcdc7d7090fab051536303cba3ba1f17860da980
[email protected] , version 1.4 — 4512389444a767f12211beeb5f2ad165aca4a558e88e8f111affb30b77ed6a5a
[email protected] , version 1.4 — e5c9a29d5ba0f53a49d8b333bfab17bf9878f94e8c3f325f5afacad44bb26fb5
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
