Socket Threat Research identified 16 malicious Firefox extensions impersonating Rabby Wallet, OKX Wallet, and browser utilities to harvest cryptocurrency recovery phrases and private keys. Four contained modified Rabby applications, while 12 used OKX-derived phishing interfaces. Functioning variants attempted to send raw wallet secrets to attacker-controlled Cloudflare Workers endpoints, despite every extension manifest declaring no data collection. One compact variant could not execute its theft workflow because of packaging and message-handler defects. Mozilla had unpublished the extensions by October 5, 2026.
Shared code, infrastructure, and the campaign marker EQOx7EIPZSNi led Socket to link the operation with high confidence to a campaign it reported in August 2026. The activity involved malicious wallet impersonation, not a vulnerability in legitimate wallet services. Users who entered recovery phrases or private keys into a functioning variant should treat the affected wallets as compromised, remove the extensions, create replacement wallets in a clean environment, and transfer their assets; removing the extension alone does not invalidate stolen secrets.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Socket published its findings on October 7, 2026, detailing raw-secret exfiltration, malicious extension identifiers, code hashes, and collection endpoints. It assessed with high confidence that the activity continued the August operation and advised exposed users to create new wallets on clean devices and transfer their assets.
Mozilla had unpublished the 16 malicious Firefox extensions by October 5, 2026. Their removal did not invalidate any recovery phrases or private keys already stolen.
Socket identified a cryptocurrency wallet-theft operation in August 2026. Researchers later linked the newly discovered extensions to that operation through reused infrastructure, tactics, wallet lures, and the campaign marker EQOx7EIPZSNi.
Attackers distributed four modified Rabby Wallet clones and twelve OKX-style extensions designed to collect recovery phrases or private keys and transmit them to attacker-controlled Cloudflare Workers. One OKX-style package contained theft code but could not execute it through its normal packaged workflow.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.