Top Highlights
- Malicious Firefox extensions are stealing cryptocurrency recovery phrases and private keys by intercepting wallet import data and exfiltrating them to attacker-controlled servers.
- Numerous browser extensions disguise as legitimate tools to harvest user data, monitor browsing habits, and redirect users to phishing or malicious sites, often evading detection.
- Some extensions are covertly sending browser activity, chat conversations, and user interactions to third-party servers, posing significant privacy and security risks.
Threat, Attack Techniques, and Targets
Cybersecurity researchers found 16 malicious Firefox extensions. These extensions pretend to be legitimate wallet tools, like Rabby and OKX Wallet. The attackers use fake wallet interfaces to trick users into entering their recovery phrases and private keys. The code of these extensions intercepts user input during wallet imports. Then, they send this secret information to attacker-controlled servers hosted on Cloudflare Workers. The malicious extensions contact a specific domain, “*.icy-star-f45c.workers.dev,” to exfiltrate data.
Most of these extensions are clones. Four are copies of Rabby Wallet, and the rest are targeted clones of OKX Wallet. The attackers keep changing package names, extension IDs, and versions. Despite the changes, they reuse the same wallet interfaces and network infrastructure. The activity appears to be a continuation of an earlier campaign from August 2026. The goal is to steal cryptocurrency recovery phrases by deceiving users during wallet setup.
Impact, Security Implications, and Remediation Guidance
If users installed these extensions and entered their recovery phrases, they are likely compromised. The stolen secrets could allow attackers to access and control users’ cryptocurrency wallets. This situation poses a serious security risk, as assets could be stolen. Users and organizations should review and remove any suspicious extensions, especially those pretending to be wallet tools.
Since the extensions have been removed as of October 5, 2026, any victim who entered sensitive information should assume their accounts are compromised. They should create new wallets on clean systems and transfer their assets securely. To prevent future issues, users should seek updated guidance from the extensions’ official vendors or security authorities on proper remediation steps and how to protect their information effectively.
Stay Ahead with the Latest Tech Trends
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
