What happened
Security researchers have identified 16 malicious Firefox extensions posing as wallet-related tools, built specifically to steal cryptocurrency recovery phrases and private keys. Four of the extensions impersonate Rabby Wallet, while the remaining twelve impersonate OKX Wallet, each listed under innocuous names such as desktop utilities or "web tools" add-ons.
Once installed, the extensions intercept recovery phrases and private keys entered during legitimate wallet import flows, then quietly exfiltrate that data to attacker-controlled infrastructure hosted on Cloudflare Workers. Every flagged add-on was found reaching out to the same backend domain — a strong signal that all 16 extensions trace back to one operation rather than copy-cat actors working independently.
Analysts assess this as a continuation of a similar campaign first spotted in August 2026, with the same group rotating extension names, version numbers, listing descriptions, and IDs while reusing the same wallet interfaces, credential-capture logic, and backend infrastructure between waves — a pattern built to survive takedowns and keep slipping past store review.
The flagged extensions had been removed as of October 5, 2026.
Why it matters
Browser extension stores remain one of the easiest distribution channels for crypto-targeting malware, because wallet recovery phrases are high-value, one-shot credentials — once an attacker captures one, there's no password reset that undoes the theft. The reuse of listing templates and a rapid republishing cycle mean a takedown doesn't close the campaign; it only forces a rename.
This also isn't an isolated incident. In the same window, researchers separately disclosed overlapping extension-based threats: a fake identity-verification add-on hijacking browser session cookies, a cluster of dozens of lookalike Chrome and Edge extensions harvesting browsing data and silently redirecting active tabs, a wave of crypto-phishing extensions built to dodge English-language analysis environments, and extensions that intercept full AI chatbot conversations (ChatGPT, Gemini, Claude, Copilot, and others) or execute attacker-issued commands fetched from a remote server to collect browsing history and fingerprinting data. Taken together, the pattern shows extension stores being treated as a reliable, low-cost delivery channel by multiple, unrelated threat actors — not a one-off.
What to do
- Anyone who installed one of the 16 flagged extensions and entered a real recovery phrase or private key should treat that wallet as compromised: move funds to a new wallet generated on a clean, trusted device, and never reuse the exposed seed phrase.
- Audit installed browser extensions across your organization — especially anything related to wallets, VPNs, ad/pop-up blockers, or generic "utility" tools — and remove anything unused or unverifiable.
- Only install wallet-related extensions directly from the official project's documented source, and verify the publisher before starting any import or recovery flow.
- In managed environments, enforce extension allowlisting, monitor for newly installed add-ons, and deploy behavior-based extension monitoring that flags unexpected outbound connections — store review alone is not sufficient protection.
