DKDKCISSPSearch
Threat Research

16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys.

DKCISSP News DeskThe Hacker News8 Oct 2026, 3:16 pm
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys.

Four of these extensions are clones of Rabby Wallet, while the rest are targeted clones of OKX Wallet.

All the identified add-ons barring one have been found to contact the domain.

Users who have installed any of the aforementioned extensions and entered a real recovery phrase or private key into the fake wallet interfaces should assume compromise, create a new wallet from a clean system, and move their assets.

The findings coincide with the discovery of several malicious or sketchy extensions for Firefox, Google Chrome, and Microsoft Edge in recent months - To counter the threat associated with malicious extensions, users are advised to review the browser extensions installed in their environment, and remove those that are no longer needed.

The activity is assessed to be a continuation of an earlier wave that the application security company documented in August 2026.

The findings suggest that the threat actors are rotating package names, versions, extension IDs, descriptions, and the presentation layer, while reusing the same wallet interfaces, credential-handling logic, and network infrastructure.

Organizations are recommended to audit extensions within managed environments, adopt runtime monitoring approaches, and deploy behavior-based extension monitoring technologies to detect suspicious activity.

The end goal is to collect mnemonic phrases and private keys and exfiltrate them to the Cloudflare Workers domain.

As of October 5, 2026, all the extensions have been removed.

What happened

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys.

Four of these extensions are clones of Rabby Wallet, while the rest are targeted clones of OKX Wallet.

All the identified add-ons barring one have been found to contact the domain.

What changed

Users who have installed any of the aforementioned extensions and entered a real recovery phrase or private key into the fake wallet interfaces should assume compromise, create a new wallet from a clean system, and move their assets.

The findings coincide with the discovery of several malicious or sketchy extensions for Firefox, Google Chrome, and Microsoft Edge in recent months - To counter the threat associated with malicious extensions, users are advised to review the browser extensions installed in their environment, and remove those that are no longer needed.

The activity is assessed to be a continuation of an earlier wave that the application security company documented in August 2026.

Who is affected

The findings suggest that the threat actors are rotating package names, versions, extension IDs, descriptions, and the presentation layer, while reusing the same wallet interfaces, credential-handling logic, and network infrastructure.

Organizations are recommended to audit extensions within managed environments, adopt runtime monitoring approaches, and deploy behavior-based extension monitoring technologies to detect suspicious activity.

Why it matters

The end goal is to collect mnemonic phrases and private keys and exfiltrate them to the Cloudflare Workers domain.

As of October 5, 2026, all the extensions have been removed.

Attribution

The Hacker News: Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Microsoft Teams to get support for third-party deepfake detection toolsBleepingComputer · 8 Oct 2026, 5:38 pmMicrosoft Outlook to block MSIX attachments starting NovemberBleepingComputer · 7 Oct 2026, 9:14 pmChina-Linked JDY Botnet Expands to 1,500+ Devices for Cyber ReconnaissanceThe Hacker News · 7 Oct 2026, 8:28 pmHalf of Cybersecurity Pros Still Rely on Passwords Despite Security CoInfosecurity Magazine · 7 Oct 2026, 3:45 pm