Socket: 16 malicious Firefox add-ons cloned Rabby and OKX wallets to steal recovery phrases and private keys, sending them to Cloudflare Workers; all removed by 5 October
Socket Threat Research reported on 7 October 2026 a campaign of 16 malicious Firefox extensions posing as cryptocurrency wallet portals, desktop utilities and browser tools. Four were clones of Rabby Wallet (shown as 'Raabby WaIIet') that hooked mnemonic and private-key import and sent the raw secret in GET parameters to a Cloudflare Worker; twelve were clones of OKX Wallet, eleven of which forwarded 12- or 24-word phrases from a background script, and one shipped broken. Fifteen contacted icy-star-f45c[.]workers[.]dev and the broken one fondationanimalaidrelief[.]workers[.]dev. Every manifest declared Firefox data-collection permission 'none' despite the code. Socket links the operators to an August 2026 wave and says they rotate names, versions, IDs and descriptions while reusing code and infrastructure. All the extensions had been removed from Mozilla's add-ons site by 5 October. Anyone who entered a real recovery phrase or private key into one should treat the wallet as compromised and move funds to a new wallet created on a clean system. Primary: Socket; wire: The Hacker News.
- Product
- Mozilla Firefox add-ons (malicious third-party extensions)
- Versions
- n/a
- Exploited in Australia?
- unknown
- Patch to
- Remove unknown wallet extensions; block outbound requests to the listed workers.dev hosts; move funds if a seed phrase was typed into one. Organisations: allow-list browser extensions in managed Firefox.
Primary: Socket — 16 malicious Firefox extensions steal cryptocurrency wallet credentials (7 Oct 2026) · The Hacker News — 16 malicious Firefox extensions pose as Rabby and OKX wallets (8 Oct 2026)
