Feeds.Feedburner 16 Malicious Firefox Extensions Target Crypto Wallets to Steal Credentials
Article Content
- •16 malicious Firefox extensions impersonate Rabby and OKX wallets.
- •Extensions steal recovery phrases and private keys, sending them to attacker-controlled domains.
- •Mozilla removed the extensions on October 5, 2026; users must create new wallets if compromised.
Researchers have identified 16 malicious Firefox extensions that impersonate popular cryptocurrency wallets, Rabby and OKX, to steal recovery phrases and private keys. These extensions masquerade as legitimate tools but intercept sensitive information during wallet import processes, sending it to attacker-controlled Cloudflare Workers. Four extensions are clones of Rabby Wallet, while the remaining twelve target OKX Wallet users. The campaign is a continuation of similar credential-stealing operations identified in August 2026. All malicious extensions were unpublished by Mozilla as of October 5, 2026. Users who interacted with these extensions should assume their wallets are compromised and create new wallets immediately. The malicious extensions utilize rotating package names and IDs to evade detection, with fifteen identified using the same domain for exfiltration.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track OKX Clone Web3 Portal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What should I do if I used these extensions?
How can I identify the malicious extensions?
What are the indicators of compromise?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…