Sixteen malicious Firefox extensions have been discovered by cybersecurity researchers, aiming to steal recovery phrases and private keys from cryptocurrency users. The dangerous add-ons mimic well-known wallets such as Rabby Wallet and OKX Wallet, tricking users into entering their secret credentials into fake interfaces. According to The Hacker News, the discovery was made by researcher Joseph Edwards of Socket, who observed that the stolen data is sent to an infrastructure controlled by the attackers via Cloudflare Workers.

The malicious Firefox extensions were disguised as wallet portals, desktop utilities, and browser add-ons. Four of them were clones of Rabby Wallet — a popular Ethereum wallet with around 900,000 users in the Chrome Web Store and 500,000 downloads in Google Play — while the remaining twelve targeted users of OKX Wallet , a major Web3 wallet with over 1 million users in the Chrome Web Store . Fifteen of the sixteen extensions communicated with icy-star-f45c.workers[.]dev , while one used an alternative domain while maintaining the same infrastructure.
view-focus-bright@webtools.co@6.12.2
quick-track-nest@tabtools.co@8.1.18
vibe-kit-tool@fasttools.co@9.21.9
edge-hub-snap@protools.net@4.12.24
core-hub-peak@neattools.example@8.24.21
sipoo-grozza@browserweb.com@2.1
mozart-seo@webtools.com@1.4
clean-file-bar@neattools.com@4.21.8
clean-net-timer@plugify.example@4.17.1
manager-square@webtools.com@1.4
manager-course@webtools.com@1.4
val-andrew@browserweb.com@1.4
manager-team@browserweb.com@1.4
valory-andrew@browserweb.com@1.4
franklin-uk@browserweb.com@1.4
franklin-uro@browserweb.com@1.4
See also: 108 malicious Chrome extensions steal Google and Telegram data
This campaign is not an isolated incident. Socket researchers assess it as a continuation of previous activity documented in August 2026, with the attackers alternating package names, versions, extension identifiers, and descriptions, while reusing the same wallet interfaces, credential management logic, and network infrastructure. This tactic makes detection difficult and demonstrates a high level of organization by the attacker group.

Critical point: Possession of a recovery phrase is not simply equivalent to password theft. An attacker who obtains the phrase can recreate the wallet on any device, sign transactions, and completely empty the funds — without needing access to the victim’s device or the wallet password.
Broader threat landscape: Malicious extensions and cryptocurrencies
The findings coincide with the discovery of several malicious or controversial extensions for Firefox, Google Chrome, and Microsoft Edge in recent months –
- ID-Pay: Malicious Firefox extension that appears as an identity verification for PDFs, but can download payload and inject JavaScript into
accounts.google.comto steal session cookies.
- 32 malicious extensions: Appear as productivity tools in Chrome and Edge, but track user activity, collect data, and can secretly redirect active tabs to malicious addresses. The campaign has been ongoing since March 2025.
- Crypto extensions: Approximately 30 extensions pretend to be legitimate productivity, privacy or cryptocurrency tools and lead users to phishing pages, aiming to steal recovery phrases from crypto wallets.
- 31 Russian-speaking VPN extensions: They are advertised as solutions for accessing blocked services, but they route traffic through proxy servers obtained from remote sources, such as GitHub Pages, Blogger, and Telegram.
- Stylish: Malicious Chrome extension that allegedly intercepts conversations from ChatGPT, Gemini, Claude, Perplexity, Character.AI, and GitHub Copilot and sends them to its administrator.
- Urban VPN: The anti-phishing feature doesn't display warnings, and the extension transmits URLs users visit to external servers. The company has also been at the center of concerns in the past about data from AI chatbots.
- Poper Blocker: It is presented as an ad blocker, but has a mechanism that receives and executes commands from a C2 server, allowing the collection of browser fingerprints, browsing history, social media information and data from interactions with AI chatbots.
See also: Malicious Firefox extensions steal crypto wallets

What Firefox extensions and cryptocurrency users should do
Anyone who has installed any of the detected extensions and has entered a real recovery phrase or private key into the fake wallet interfaces should consider themselves compromised. The recommended steps are: create a new wallet from a clean system, transfer funds to the new wallet, and revoke token authorizations associated with the exposed wallet. The exposed recovery phrase, private key , or password should never be reused.
See also: Chrome & Firefox: Fix critical use-after-free vulnerabilities
For added security, it is recommended to use hardware wallets for significant funds and verify transaction details on the physical device. Recovery phrases should be stored offline — no legitimate support member will ever ask for them. The availability of an extension on an official marketplace is no guarantee of authenticity: malicious code can evade initial review, be uploaded under misleading names, or be introduced via later updates.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
