Home / Companies / Socket / Blog / Post Details
Content Deep Dive

16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials

Blog post from Socket

Post Details
Company
Date Published
Author
Joseph Edwards
Word Count
2,226
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket Threat Research identified 16 malicious Firefox extensions that impersonated Rabby Wallet or OKX Wallet interfaces to steal cryptocurrency recovery phrases and private keys, transmitting the secrets to attacker-controlled Cloudflare Workers despite declaring that they collected no user data. Four larger extensions repackaged substantial Rabby codebases under the misspelled “Raabby WaIIet” brand and captured mnemonic phrases and raw private keys through multiple import-flow hooks, while 12 smaller extensions used an OKX-like “Portal WALLET” interface to solicit 12- or 24-word recovery phrases. The campaign reused common code, infrastructure, and the marker “EQOx7EIPZSNi,” linking it with high confidence to an earlier crypto-theft extension operation, although one variant was nonfunctional because its background script was not properly loaded. Mozilla had removed the identified extensions by October 5, 2026, but users who entered credentials are advised to consider affected wallets compromised, create replacement wallets from a clean device, move assets, revoke token approvals, and review synchronized Firefox profiles. Defenders are advised to block the listed extensions and related infrastructure, hunt for shared code markers and hashes, and ensure that monitoring systems redact stolen-secret fields rather than preserving them in logs.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.