Hackers Use Fake Firefox Wallet Extensions to Steal Crypto Recovery Phrases

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers have used 16 malicious Firefox extensions to target cryptocurrency users with fake wallet screens that capture recovery phrases and private keys.

The add-ons posed as wallet portals, desktop tools, and browser utilities, while hidden code attempted to send the secrets to attacker-controlled Cloudflare Workers.

The campaign copied interfaces from Rabby Wallet and OKX Wallet, turning familiar wallet import steps into traps. Mozilla had removed the malicious extensions from its marketplace by October 5, 2026.

However, removal does not protect anyone who already entered a recovery phrase or private key into a working version. Researchers from Socket.dev identified the malware and published their findings on October 7.

Their analysis found four large Rabby clones and 12 smaller OKX-style extensions. Eleven smaller packages loaded credential-stealing background scripts; one contained similar theft code but could not run it through its normal packaged workflow.

Socket linked the activity with high confidence to an August campaign based on shared code, infrastructure, and a common tracking marker.

The earlier Firefox wallet theft campaign also used fake wallet interfaces and Cloudflare Workers to collect secrets, showing how attackers can keep publishing related packages under changing names.

Hackers Use Fake Firefox Wallet Extensions

Each Rabby clone contained 1,114 files, including wallet import screens, account management code, and transaction interfaces.

Rather than building a simple phishing page, the operators copied a substantial wallet application and added theft functions. Some official Rabby links and DeBank service settings remained, helping the altered software look more convincing.

The stolen branding was inconsistent: the welcome screen still displayed Rabby Wallet, while other parts used a misspelled name. More importantly, malicious functions were placed directly after private-key and recovery-phrase import operations.

They accepted 12-word or 24-word phrases and 64-character hexadecimal private keys, copying the same secrets the wallet processed. This approach exploits trust in a familiar screen rather than proving a flaw in the real wallet service.

Similar fake crypto wallet screens have appeared in separate malware campaigns, where convincing recovery prompts persuade users to surrender secrets. Here, the copied application could continue its wallet workflow while the theft code ran alongside it.

Rabby Clone Interface (Source - Socket.dev)
Rabby Clone Interface (Source – Socket.dev)

The smaller extensions displayed an OKX-derived interface under generic portal branding. Their import form checked for exactly 12 or 24 words, then passed the entered phrase to a background handler.

That handler removed surrounding spaces, rejected empty input, and avoided sending repeated phrases already seen during the running session.

Secrets Sent Through Cloudflare Workers

The Rabby clones sent secrets inside GET request URLs, with a second request method available if the first failed. This exposed recovery material not only to the attacker’s endpoint but also to systems that record request URLs.

The active OKX-style handlers instead sent raw phrases in HTTPS POST requests containing JSON data. One packaged background script offered three sending methods: a browser beacon, a POST request, and an image-based GET fallback.

Its comments claimed that only a hash and word count left the device. Socket found that the payload contained the full phrase; the hash served only to prevent duplicate submissions.

The broken extension lacked the manifest entry needed to load its background script, and its interface sent a message the handler did not accept. That limits claims about its operation, not its intent.

Separate TronLink wallet impersonation attacks likewise show how copied wallet interfaces can become credential traps, although those attacks used different delivery and collection methods.

Every extension declared that it collected no data, contradicting the secret-handling code. The Rabby clones also requested broad browser access.

However, Socket’s static analysis did not establish a separate form-grabbing capability, so the confirmed finding remains wallet-secret theft rather than wider browsing-data collection.

Legitimate Rabby and DeBank domains retained in the packages are not campaign indicators. Anyone who entered a real phrase or private key into a working variant should treat the wallet as compromised.

Socket recommends removing the extensions, creating a new wallet on a clean device, moving assets, and revoking relevant token approvals. Changing the extension password cannot invalidate a stolen recovery phrase or private key.

Defenders should check extension inventories, browser profiles, synchronized add-ons, and network records against the indicators below.

Searches should match destination hosts, request patterns, hashes, and campaign markers without copying stolen phrases into alerts or case notes.

The secret-bearing field should be redacted. Preserve suspicious packages for investigation, but do not run them on an analyst’s normal workstation.

Indicators of compromise (IoCs):-

Network and Code Indicators

Type Indicator Purpose
Network endpoint hxxps://silent-wind-get[.]icy-star-f45c[.]workers[.]dev/ Rabby-clone secret collection
Network endpoint hxxps://small-boat-969c[.]icy-star-f45c[.]workers[.]dev/ OKX-style secret collection
Network endpoint hxxps://green-firefly-ab28[.]icy-star-f45c[.]workers[.]dev/ OKX-style secret collection
Network endpoint hxxps://flat-wildflower-f954[.]fondationanimalaidrelief[.]workers[.]dev/ Endpoint packaged in the broken variant
Campaign marker EQOx7EIPZSNi Shared campaign token
Fake branding Raabby WaIIet Rabby-clone detection string
Runtime message SEED_PHRASE_IMPORT Recovery-phrase submission
Runtime message WALLET_SYNC Legacy message handled by theft code

Shared File Hashes

File or Component SHA-256
Rabby-clone background.js 7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799
OKX core background.js da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd
Broken variant background.js be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897
OKX Web3 Portal background.js c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f
Shared compact frontend eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf

Extension IDs and Package Hashes

Firefox Extension ID Version XPI SHA-256
[email protected] 6.12.2 2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51
[email protected] 8.1.18 225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b
[email protected] 9.21.9 6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8
[email protected] 4.12.24 8906dd85b0991fac14e5973b3f3f61d93ef1101504cb5867a004c762ee184ef7
[email protected] 8.24.21 9fea0ee3c81047f5e50eeb3a2ab2a7cd70357f3e49944b7079ab3e90c9ea0e8b
[email protected] 2.1 0aed5f24ce625ee6b9422083302766f74b0b9a57e1b18213328b950cc7057e35
[email protected] 1.4 635b31b4a19b5673fcbe0fedeb3f7ed2c27fddb739685f19ca5f3d1f1d7f0083
[email protected] 4.21.8 d9432e41e0401715bce4ce11f4a7104d94fab1ec89be553ba57a2097e418c1a1
[email protected] 4.17.1 458e7255438f15aaede02fd7f8fcfdf762aa6e08608b9546fe8aa8aa399c76b7
[email protected] 1.4 bb8f60b3f77d96adc93bf0515b34df7c5f1f560a9f6d0c353b7d849609e3557d
[email protected] 1.4 71ec70479ab78efb1e1f9507f8ff7348d5711c837cc50a0120f3a188c340f3f4
[email protected] 1.4 e96c75cd0c9b35000b4a3ec12d5dd23ca157e94aee7271a0fe8d8d7c9f2e9096
[email protected] 1.4 faf174414ddc7099360c4ae4d16497b9846cfae71ffad5bbab820bba657f94d3
[email protected] 1.4 b02ae1d5a0d2a5b28f8baa2afcdc7d7090fab051536303cba3ba1f17860da980
[email protected] 1.4 4512389444a767f12211beeb5f2ad165aca4a558e88e8f111affb30b77ed6a5a
[email protected] 1.4 e5c9a29d5ba0f53a49d8b333bfab17bf9878f94e8c3f325f5afacad44bb26fb5

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Hackers Use Fake Firefox Wallet Extensions to Steal Crypto Recovery Phrases appeared first on Cyber Security News.