16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Blog post from Socket
Socket Threat Research identified 16 malicious Firefox extensions that impersonated Rabby Wallet or OKX Wallet interfaces to steal cryptocurrency recovery phrases and private keys, transmitting the secrets to attacker-controlled Cloudflare Workers despite declaring that they collected no user data. Four larger extensions repackaged substantial Rabby codebases under the misspelled “Raabby WaIIet” brand and captured mnemonic phrases and raw private keys through multiple import-flow hooks, while 12 smaller extensions used an OKX-like “Portal WALLET” interface to solicit 12- or 24-word recovery phrases. The campaign reused common code, infrastructure, and the marker “EQOx7EIPZSNi,” linking it with high confidence to an earlier crypto-theft extension operation, although one variant was nonfunctional because its background script was not properly loaded. Mozilla had removed the identified extensions by October 5, 2026, but users who entered credentials are advised to consider affected wallets compromised, create replacement wallets from a clean device, move assets, revoke token approvals, and review synchronized Firefox profiles. Defenders are advised to block the listed extensions and related infrastructure, hunt for shared code markers and hashes, and ensure that monitoring systems redact stolen-secret fields rather than preserving them in logs.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.