CyberSecurityNews

Hackers Use Fake Firefox Wallet Extensions to Steal Crypto Recovery Phrases


Hackers have used 16 malicious Firefox extensions to target cryptocurrency users with fake wallet screens that capture recovery phrases and private keys.

The add-ons posed as wallet portals, desktop tools, and browser utilities, while hidden code attempted to send the secrets to attacker-controlled Cloudflare Workers.

The campaign copied interfaces from Rabby Wallet and OKX Wallet, turning familiar wallet import steps into traps. Mozilla had removed the malicious extensions from its marketplace by October 5, 2026.

However, removal does not protect anyone who already entered a recovery phrase or private key into a working version. Researchers from Socket.dev identified the malware and published their findings on October 7.

Their analysis found four large Rabby clones and 12 smaller OKX-style extensions. Eleven smaller packages loaded credential-stealing background scripts; one contained similar theft code but could not run it through its normal packaged workflow.

Socket linked the activity with high confidence to an August campaign based on shared code, infrastructure, and a common tracking marker.

The earlier Firefox wallet theft campaign also used fake wallet interfaces and Cloudflare Workers to collect secrets, showing how attackers can keep publishing related packages under changing names.

Hackers Use Fake Firefox Wallet Extensions

Each Rabby clone contained 1,114 files, including wallet import screens, account management code, and transaction interfaces.

Rather than building a simple phishing page, the operators copied a substantial wallet application and added theft functions. Some official Rabby links and DeBank service settings remained, helping the altered software look more convincing.

The stolen branding was inconsistent: the welcome screen still displayed Rabby Wallet, while other parts used a misspelled name. More importantly, malicious functions were placed directly after private-key and recovery-phrase import operations.

They accepted 12-word or 24-word phrases and 64-character hexadecimal private keys, copying the same secrets the wallet processed. This approach exploits trust in a familiar screen rather than proving a flaw in the real wallet service.

Similar fake crypto wallet screens have appeared in separate malware campaigns, where convincing recovery prompts persuade users to surrender secrets. Here, the copied application could continue its wallet workflow while the theft code ran alongside it.

Rabby Clone Interface (Source – Socket.dev)

The smaller extensions displayed an OKX-derived interface under generic portal branding. Their import form checked for exactly 12 or 24 words, then passed the entered phrase to a background handler.

That handler removed surrounding spaces, rejected empty input, and avoided sending repeated phrases already seen during the running session.

Secrets Sent Through Cloudflare Workers

The Rabby clones sent secrets inside GET request URLs, with a second request method available if the first failed. This exposed recovery material not only to the attacker’s endpoint but also to systems that record request URLs.

The active OKX-style handlers instead sent raw phrases in HTTPS POST requests containing JSON data. One packaged background script offered three sending methods: a browser beacon, a POST request, and an image-based GET fallback.

Its comments claimed that only a hash and word count left the device. Socket found that the payload contained the full phrase; the hash served only to prevent duplicate submissions.

The broken extension lacked the manifest entry needed to load its background script, and its interface sent a message the handler did not accept. That limits claims about its operation, not its intent.

Separate TronLink wallet impersonation attacks likewise show how copied wallet interfaces can become credential traps, although those attacks used different delivery and collection methods.

Every extension declared that it collected no data, contradicting the secret-handling code. The Rabby clones also requested broad browser access.

However, Socket’s static analysis did not establish a separate form-grabbing capability, so the confirmed finding remains wallet-secret theft rather than wider browsing-data collection.

Legitimate Rabby and DeBank domains retained in the packages are not campaign indicators. Anyone who entered a real phrase or private key into a working variant should treat the wallet as compromised.

Socket recommends removing the extensions, creating a new wallet on a clean device, moving assets, and revoking relevant token approvals. Changing the extension password cannot invalidate a stolen recovery phrase or private key.

Defenders should check extension inventories, browser profiles, synchronized add-ons, and network records against the indicators below.

Searches should match destination hosts, request patterns, hashes, and campaign markers without copying stolen phrases into alerts or case notes.

The secret-bearing field should be redacted. Preserve suspicious packages for investigation, but do not run them on an analyst’s normal workstation.

Indicators of compromise (IoCs):-

Network and Code Indicators

TypeIndicatorPurpose
Network endpointhxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/Rabby-clone secret collection
Network endpointhxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/OKX-style secret collection
Network endpointhxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/OKX-style secret collection
Network endpointhxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/Endpoint packaged in the broken variant
Campaign markerEQOx7EIPZSNiShared campaign token
Fake brandingRaabby WaIIetRabby-clone detection string
Runtime messageSEED_PHRASE_IMPORTRecovery-phrase submission
Runtime messageWALLET_SYNCLegacy message handled by theft code

Shared File Hashes

File or ComponentSHA-256
Rabby-clone background.js7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799
OKX core background.jsda447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd
Broken variant background.jsbe246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897
OKX Web3 Portal background.jsc550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f
Shared compact frontendeb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf

Extension IDs and Package Hashes

Firefox Extension IDVersionXPI SHA-256
view-focus-bright@webtools.co6.12.22f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51
quick-track-nest@tabtools.co8.1.18225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b
vibe-kit-tool@fasttools.co9.21.96b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8
edge-hub-snap@protools.net4.12.248906dd85b0991fac14e5973b3f3f61d93ef1101504cb5867a004c762ee184ef7
core-hub-peak@neattools.example8.24.219fea0ee3c81047f5e50eeb3a2ab2a7cd70357f3e49944b7079ab3e90c9ea0e8b
sipoo-grozza@browserweb.com2.10aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35
mozart-seo@webtools.com1.4635b31b4a19b5673fcbe0fedeb3f7ed2c27fddb739685f19ca5f3d1f1d7f0083
clean-file-bar@neattools.com4.21.8d9432e41e0401715bce4ce11f4a7104d94fab1ec89be553ba57a2097e418c1a1
clean-net-timer@plugify.example4.17.1458e7255438f15aaede02fd7f8fcfdf762aa6e08608b9546fe8aa8aa399c76b7
manager-square@webtools.com1.4bb8f60b3f77d96adc93bf0515b34df7c5f1f560a9f6d0c353b7d849609e3557d
manager-course@webtools.com1.471ec70479ab78efb1e1f9507f8ff7348d5711c837cc50a0120f3a188c340f3f4
val-andrew@browserweb.com1.4e96c75cd0c9b35000b4a3ec12d5dd23ca157e94aee7271a0fe8d8d7c9f2e9096
manager-team@browserweb.com1.4faf174414ddc7099360c4ae4d16497b9846cfae71ffad5bbab820bba657f94d3
valory-andrew@browserweb.com1.4b02ae1d5a0d2a5b28f8baa2afcdc7d7090fab051536303cba3ba1f17860da980
franklin-uk@browserweb.com1.44512389444a767f12211beeb5f2ad165aca4a558e88e8f111affb30b77ed6a5a
franklin-uro@browserweb.com1.4e5c9a29d5ba0f53a49d8b333bfab17bf9878f94e8c3f325f5afacad44bb26fb5

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC



Source link