Skip to content
16 Malicious Firefox Extensions Target Crypto Wallets to Steal Credentials

16 Malicious Firefox Extensions Target Crypto Wallets to Steal Credentials

First seen 8 Oct 2026, 10:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 11:32 UTC
  • •16 malicious Firefox extensions impersonate Rabby and OKX wallets.
  • •Extensions steal recovery phrases and private keys, sending them to attacker-controlled domains.
  • •Mozilla removed the extensions on October 5, 2026; users must create new wallets if compromised.

Researchers have identified 16 malicious Firefox extensions that impersonate popular cryptocurrency wallets, Rabby and OKX, to steal recovery phrases and private keys. These extensions masquerade as legitimate tools but intercept sensitive information during wallet import processes, sending it to attacker-controlled Cloudflare Workers. Four extensions are clones of Rabby Wallet, while the remaining twelve target OKX Wallet users. The campaign is a continuation of similar credential-stealing operations identified in August 2026. All malicious extensions were unpublished by Mozilla as of October 5, 2026. Users who interacted with these extensions should assume their wallets are compromised and create new wallets immediately. The malicious extensions utilize rotating package names and IDs to evade detection, with fifteen identified using the same domain for exfiltration.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-01
Previous campaign identified
Socket identified a similar campaign targeting cryptocurrency wallet users, indicating ongoing threats.
Socket.Dev
2026-10-05
Mozilla removes malicious extensions
All identified malicious Firefox extensions were unpublished from the Firefox Add-ons store.
Socket.Dev

More articles in this cluster (4)

Following this threat?

Track OKX Clone Web3 Portal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What should I do if I used these extensions?
Create a new cryptocurrency wallet from a clean environment and transfer your assets immediately.
How can I identify the malicious extensions?
The extensions include names like [email protected] and [email protected] among others.
What are the indicators of compromise?
Look for unusual activity in your cryptocurrency wallet and ensure you have not entered recovery phrases into any suspicious extensions.