Sixteen add-ons copied cryptocurrency wallet interfaces
A cluster of 16 malicious Mozilla Firefox extensions impersonated Rabby Wallet, OKX Wallet and related browser utilities to capture cryptocurrency wallet credentials.
According to an analysis attributed to Socket researcher Joseph Edwards, the add-ons targeted recovery phrases and private keys entered during wallet-import procedures. Their code then attempted to transmit those secrets to attacker-controlled infrastructure hosted on Cloudflare Workers.
Four extensions were described as Rabby Wallet clones, while the remaining 12 targeted OKX Wallet users. The available reporting does not map individual extension identifiers to either brand.
There is no indication in the cited findings that the legitimate Rabby Wallet or OKX Wallet products were compromised. Instead, the operation relied on counterfeit extensions designed to resemble trusted wallet software.
The 16 add-ons represent 16 malicious software records, not 16 confirmed victims. The report provides no victim count, verified theft total or evidence that a particular user lost cryptocurrency.
According to the report, all identified extensions had been removed as of October 5, 2026. Removal from an extension store does not by itself tell users whether one of the listed add-ons remains present in an existing Firefox profile, so direct inspection is still warranted.
The credential theft occurs during wallet import
The malicious extensions presented themselves as wallet portals, desktop-style utilities or browser tools. The dangerous behavior appeared when a user attempted to import an existing wallet.
Importing a cryptocurrency wallet commonly requires highly sensitive material, such as a recovery phrase or private key. In the reported extensions, code intercepted those values when they were submitted through the fake interface and tried to send them to infrastructure controlled by the operators.
That distinction matters when assessing exposure. Installing one of the extensions created a potential risk, but the report’s most urgent remediation advice applies to people who also entered a genuine recovery phrase or private key.
Possession of either secret may allow an attacker to take control of the associated wallet and transfer its assets. However, the available findings do not establish that every add-on successfully transmitted captured data, that every installation reached the import stage or that any specific wallet was drained.
All but one of the extensions reportedly communicated with:
*.icy-star-f45c.workers[.]dev
The material does not identify which add-on was the exception. It also provides no additional infrastructure indicators.
Cloudflare Workers was used as hosting infrastructure in this activity, according to the analysis. That does not indicate that Cloudflare itself participated in the operation or that its broader platform was compromised.
Changing identities helped preserve the underlying operation
Socket assessed the cluster as a continuation of malicious extension activity it documented in August 2026. The connection was based on repeated technical and design elements rather than identical store listings.
According to the researchers, the operators changed package names, version numbers, extension IDs, descriptions and visual presentation. At the same time, they reused wallet interfaces, credential-processing logic and network infrastructure.
This rotation can complicate detection based only on an extension’s public name or description. An add-on removed under one identity can be repackaged with different metadata while retaining the code paths and servers that support credential theft.
The assessment indicates continuity between the observed waves, but the supplied findings do not identify the operators or attribute them to a named threat group. They also do not specify when each extension was published, installed or first used against a target.
No CVE identifier or formal severity rating applies in the cited material. This is described as a malicious-extension campaign rather than exploitation of a documented vulnerability in Firefox, Rabby Wallet or OKX Wallet.
The complete list of reported extensions
Users and administrators should compare installed Firefox extensions against the exact identifiers and versions below:
[email protected]@6.12.2[email protected]@8.1.18[email protected]@9.21.9[email protected]@4.12.24[email protected]@8.24.21[email protected]@2.1[email protected]@1.4[email protected]@4.21.8[email protected]@4.17.1[email protected]@1.4[email protected]@1.4[email protected]@1.4[email protected]@1.4[email protected]@1.4[email protected]@1.4[email protected]@1.4
The identifiers should be treated as the reliable comparison points because the operators reportedly changed names, descriptions and other presentation details. The report does not specify which four entries imitated Rabby Wallet and which 12 imitated OKX Wallet.
Store removal status should not replace local verification. Users can review Firefox’s installed add-ons and remove any matching entry, along with extensions they no longer recognize or need.
Anyone who submitted a secret should migrate wallets
A user who entered a real recovery phrase or private key into one of these interfaces should treat the corresponding wallet as compromised, according to the report.
Simply uninstalling the extension does not revoke a secret that may already have been captured. The recommended response is to create a new wallet from a clean system and move the assets from the potentially exposed wallet to the new one.
The sequence is important:
- Use a clean device or system environment.
- Create a new wallet with newly generated credentials.
- Transfer assets away from the wallet associated with the exposed phrase or key.
- Remove the malicious extension and review other installed browser add-ons.
Users should not import the potentially exposed recovery phrase into the replacement wallet, because doing so would preserve the compromised credential rather than replace it.
Organizations managing Firefox installations should audit deployed extensions across their environments. The report also recommends runtime and behavior-based monitoring capable of identifying suspicious extension activity, including attempts to collect credentials or communicate with unexpected remote services.
The available material does not provide confirmed victim notifications or asset-loss figures. Therefore, exposure should be assessed from local evidence: whether a listed extension was installed and whether genuine wallet credentials were entered into it.
Separate extension campaigns show broader browser risk
The report also discusses other malicious or questionable browser extensions, but it does not present them as part of this 16-extension wallet cluster.
One separate Firefox extension, identified as [email protected] and named “ID- Pay,” reportedly impersonates an identity-verification utility for protected PDF documents. It can allegedly retrieve a remote payload and inject JavaScript into accounts.google[.]com to steal session cookies.
Another distinct cluster comprises 32 Chrome and Edge extensions posing as productivity tools. That campaign, reportedly active since March 2025, collects data, monitors browsing and can replace the active tab using remotely supplied configuration. The report attributes it to a Korean-speaking threat actor.
Other cited cases involve wallet-phishing redirects, Russian-language proxy extensions and add-ons accused of collecting AI chatbot conversations or executing remotely delivered instructions. Those examples provide context for the abuse of browser-extension privileges, but they should not be conflated with the fake Rabby and OKX add-ons.
For the Firefox wallet cluster, the clearest risk boundary is narrow: users who installed one of the 16 listed extensions and disclosed a real recovery phrase or private key face the most direct danger. The absence of confirmed loss figures does not reduce the sensitivity of those credentials.




