OKX, Mozilla and DeBank: 16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

OKX, Mozilla and DeBank: 16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

Malicious Firefox Extensions Target Cryptocurrency Wallets in Sophisticated Phishing Campaign

On October 7, 2026, cybersecurity firm Socket disclosed the discovery of 16 malicious Firefox extensions designed to steal cryptocurrency wallet recovery phrases and private keys. The extensions, which impersonated legitimate wallet tools like Rabby Wallet and OKX, were unpublished by Mozilla by October 5, 2026, following Socket’s investigation.

How the Attack Worked

The extensions masqueraded as wallet portals, desktop utilities, and browser tools, embedding malicious code within otherwise functional interfaces. Key details include:

  • Deceptive Branding: Four extensions cloned Rabby Wallet, using the misspelled name "Raabby WaIIet" and retaining legitimate assets from DeBank to appear authentic. Each contained 1,114 files, including wallet import screens and transaction interfaces, making the malicious components harder to detect.
  • Secret Theft Mechanisms: The extensions intercepted 12- or 24-word recovery phrases and 64-character private keys during wallet imports. Malicious hooks in background.js and 977.js captured secrets after operations like importPrivateKey and createKeyringWithMnemonics, transmitting them to attacker-controlled Cloudflare Workers via HTTPS.
  • Exfiltration Methods: Stolen data was sent in GET/POST requests to domains like silent-wind-get.icy-star-f45c[.]workers[.]dev, often including the raw secret in the URL a risky practice that could expose it in server logs. Some extensions used navigator.sendBeacon or image-pixel GET fallbacks as redundant exfiltration paths.
  • Manifest Mismatch: Despite declaring "none" for data collection permissions in their manifests, all extensions contained code to transmit wallet secrets, highlighting deliberate deception.

Scope and Attribution

  • 15 of the 16 extensions had functional theft mechanisms, while one ([email protected] v2.1) failed due to a missing manifest declaration, preventing its background script from loading.
  • The campaign reused shared infrastructure, code, and a campaign marker (EQOx7EIPZSNi) from Socket’s August 2026 investigation, which identified 77 related extensions (40 malicious, 37 deceptive). Researchers assessed this as a continuation of the same operation, though no specific threat actor was named.
  • Smaller extensions mimicked OKX Wallet onboarding screens, using official OKX help links to bolster credibility.

Impact and Recommendations

Users who imported wallets via these extensions should assume compromise, as exposed recovery phrases and private keys cannot be invalidated by password changes. Affected individuals were advised to:

  • Remove the extensions immediately.
  • Create new wallets from a clean environment.
  • Transfer assets to secure wallets.

Defenders can block the identified Cloudflare Worker endpoints and hunt for the campaign’s indicators of compromise (IOCs), including hashes and the marker EQOx7EIPZSNi. Telemetry should redact the w parameter to avoid logging stolen secrets. Notably, legitimate Rabby and DeBank domains are not malicious, and broad permissions alone do not indicate additional data theft.

Source: https://gbhackers.com/16-malicious-firefox-extensions/

OKX TPRM report: https://www.rankiteo.com/company/okxofficial

Mozilla TPRM report: https://www.rankiteo.com/company/mozilla-corporation

DeBank TPRM report: https://www.rankiteo.com/company/debank

"id": "mozdebokx1791464232",
"linkid": "mozilla-corporation, debank, okxofficial",
"type": "Cyber Attack",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'FinTech, Cryptocurrency',
                        'name': 'Rabby Wallet (impersonated)',
                        'type': 'Cryptocurrency Wallet'},
                       {'industry': 'FinTech, Cryptocurrency',
                        'name': 'OKX (impersonated)',
                        'type': 'Cryptocurrency Exchange/Wallet'},
                       {'location': 'Global',
                        'name': 'Mozilla Firefox Extension Users',
                        'type': 'End Users'}],
 'attack_vector': 'Malicious Browser Extensions',
 'customer_advisories': 'Public disclosure and recommendations for affected '
                        'users',
 'data_breach': {'data_exfiltration': 'Transmitted to attacker-controlled '
                                      'Cloudflare Workers via HTTPS',
                 'personally_identifiable_information': 'Recovery phrases, '
                                                        'private keys '
                                                        '(indirectly linked to '
                                                        'user identities)',
                 'sensitivity_of_data': 'High (direct access to cryptocurrency '
                                        'funds)',
                 'type_of_data_compromised': 'Cryptocurrency wallet recovery '
                                             'phrases, private keys'},
 'date_detected': '2026-10-07',
 'date_publicly_disclosed': '2026-10-07',
 'date_resolved': '2026-10-05',
 'description': 'On October 7, 2026, cybersecurity firm Socket disclosed the '
                'discovery of 16 malicious Firefox extensions designed to '
                'steal cryptocurrency wallet recovery phrases and private '
                'keys. The extensions impersonated legitimate wallet tools '
                'like Rabby Wallet and OKX and were unpublished by Mozilla by '
                'October 5, 2026, following Socket’s investigation. The '
                'extensions masqueraded as wallet portals, desktop utilities, '
                'and browser tools, embedding malicious code within otherwise '
                'functional interfaces. They intercepted recovery phrases and '
                'private keys during wallet imports and transmitted them to '
                'attacker-controlled Cloudflare Workers.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to '
                                       'impersonated brands (Rabby Wallet, '
                                       'OKX)',
            'data_compromised': 'Cryptocurrency wallet recovery phrases, '
                                'private keys',
            'identity_theft_risk': 'High (exposed recovery phrases and private '
                                   'keys)',
            'operational_impact': 'Users advised to create new wallets and '
                                  'transfer assets',
            'payment_information_risk': 'High (cryptocurrency theft)',
            'systems_affected': 'Firefox browser extensions'},
 'initial_access_broker': {'backdoors_established': 'Malicious hooks in '
                                                    'background.js and 977.js',
                           'entry_point': 'Malicious Firefox extensions',
                           'high_value_targets': 'Cryptocurrency wallet users'},
 'investigation_status': 'Completed (extensions unpublished)',
 'lessons_learned': 'Deceptive branding and malicious code can evade detection '
                    'in browser extensions. Users should verify extension '
                    'authenticity and avoid granting unnecessary permissions. '
                    'Defenders should monitor for suspicious exfiltration '
                    'endpoints and redact sensitive parameters in logs.',
 'motivation': 'Financial gain (cryptocurrency theft)',
 'post_incident_analysis': {'corrective_actions': 'Unpublishing malicious '
                                                  'extensions, public '
                                                  'advisories, blocking '
                                                  'attacker infrastructure',
                            'root_causes': 'Deceptive branding, malicious code '
                                           'embedded in extensions, lack of '
                                           'user verification of extension '
                                           'authenticity'},
 'recommendations': ['Remove malicious extensions immediately',
                     'Create new wallets from a clean environment',
                     'Transfer assets to secure wallets',
                     'Block identified Cloudflare Worker endpoints',
                     'Hunt for IOCs (e.g., campaign marker `EQOx7EIPZSNi`)',
                     'Redact sensitive parameters (e.g., `w`) in telemetry to '
                     'avoid logging stolen secrets'],
 'references': [{'date_accessed': '2026-10-07', 'source': 'Socket'}],
 'response': {'communication_strategy': 'Public disclosure by Socket, '
                                        'advisories to affected users',
              'containment_measures': 'Mozilla unpublished the malicious '
                                      'extensions',
              'enhanced_monitoring': 'Blocking identified Cloudflare Worker '
                                     'endpoints, hunting for IOCs',
              'remediation_measures': 'Users advised to remove extensions, '
                                      'create new wallets, and transfer assets',
              'third_party_assistance': 'Socket (cybersecurity firm)'},
 'stakeholder_advisories': 'Users advised to assume compromise if they '
                           'imported wallets via the extensions',
 'title': 'Malicious Firefox Extensions Target Cryptocurrency Wallets in '
          'Sophisticated Phishing Campaign',
 'type': 'Phishing, Data Theft',
 'vulnerability_exploited': 'Deceptive branding, malicious hooks in JavaScript '
                            'files'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.