Crypto theft campaign escalates on Firefox: 16 additional malicious extensions flagged
A seemingly innocent timer extension transforms into a crypto wallet clone.

Malicious Firefox extensions want your money and credentials. By Cybernews.
- Researchers found 16 malicious Firefox extensions targeting Rabby and OKX wallet users.
- The extensions initially looked like ordinary tools but later asked for recovery phrases and private keys.
- Mozilla removed the extensions, but attackers keep releasing new ones, changing names and versions.
- Users who entered wallet secrets should create a new wallet in a clean environment.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Security researchers found 16 malicious Firefox extensions that initially appear as harmless casual tools, but later they start mimicking popular crypto wallets, asking for recovery phrases and private keys. Attackers are continuously releasing new extensions.
A coordinated campaign of malicious Firefox extensions is targeting users of 2 popular crypto wallets, downloaded by over a million users each: Rabby, an Ethereum wallet, and OKX, a DeFi wallet.
Victims may think they’re downloading an extension that’s unrelated to crypto. But under the facade, hidden inside the malware, are fake clones of real crypto wallets. They’re designed to intercept key credentials – fake extensions will ask users to import their crypto wallets, exposing 12/24-word recovery phrases or private keys.
“The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers,” Socket Threat Research said in the report.
The researchers warn that any user who entered a recovery phrase or private key while these extensions were active, should treat the wallet as compromised:
- [email protected]@6.12.2
- [email protected]@8.1.18
- [email protected]@9.21.9
- [email protected]@4.12.24
- [email protected]@8.24.21
- [email protected]@2.1
- [email protected]@1.4
- [email protected]@4.21.8
- [email protected]@4.17.1
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
Every extension declared in its manifest that it collects no data at all, to trick users into believing that they’re safe.
Mozilla has unpublished the malicious extensions from its add-ons store as of October 5th, 2026.
However, it doesn’t mean that campaign operators will stop – they frequently rotate package names, versions, IDs, descriptions, and overall presentation.
Socket says it’s a continuation of the previously reported crypto-theft heist, which planted at least 77 malicious Firefox extensions in August 2026.
Anyone affected should immediately migrate to a new wallet created in a clean environment, with a new recovery phrase.
Previously, thousands of Firefox users were compromised in another malicious campaign that hid malware in extension icons.