CYBERSECURITY researchers have uncovered a cluster of 16 malicious Mozilla Firefox extensions that impersonate Rabby Wallet and OKX Wallet interfaces to steal users’ recovery phrases and private keys. The extensions’ code interposes during wallet import flows, exfiltrating mnemonic phrases and private keys to attacker‑controlled Cloudflare Workers. Four of the extensions are clones of Rabby Wallet, while the remaining 12 are targeted clones of OKX Wallet.
All identified add‑ons, except one, were found to contact the domain *.icy-star-f45c.workers[.]dev, with the ultimate aim of harvesting credentials and funneling them to the attacker’s servers.
As of 5 October 2026, all of the extensions have been removed. The researchers note that the threat actors are rotating package names, versions, extension IDs, and descriptions while reusing the same wallet interfaces, credential‑handling logic, and network infrastructure. If users installed any of these extensions and entered a real recovery phrase or private key into the fake wallet interfaces, they are advised to assume compromise, create a new wallet on a clean system, and move assets accordingly.
The discovery aligns with earlier activity in 2026 documenting similar malicious extensions targeting Firefox, Chrome, and Edge, often masquerading as legitimate utilities or wallet tools to harvest sensitive credentials.