Security researchers at Socket have identified 16 malicious Firefox extensions that impersonated Rabby Wallet and OKX Wallet, along with other browser tools. The extensions were designed to steal cryptocurrency recovery phrases and private keys during wallet import flows, according to an analysis by researcher Joseph Edwards.

The malicious code intercepted secrets and transmitted them to attacker-controlled Cloudflare Workers infrastructure, specifically the domain icy-star-f45c.workers[.]dev, which all but one of the extensions contacted. The campaign appears to be a continuation of an earlier wave documented in August 2026, with attackers rotating extension names, versions, and descriptions while reusing the same wallet interfaces and credential-handling logic.

All 16 extensions were removed from Firefox by October 5, 2026. Users who entered real recovery phrases or private keys into the fake interfaces should assume their wallets are compromised, create a new wallet from a clean system, and move their assets. The findings also highlight a broader trend of malicious browser extensions across Firefox, Chrome, and Edge, including those targeting Google accounts and AI chatbot data.