16 Firefox Extensions Discovered Stealing Crypto Wallet Credentials And Private Keys

16 Firefox Extensions Discovered Stealing Crypto Wallet Credentials And Private Keys

Cybersecurity researchers have identified a group of 16 malicious Mozilla Firefox extensions designed to target cryptocurrency wallet users by attempting to steal recovery phrases and private keys. The extensions were discovered posing as legitimate wallet services, browser utilities, and desktop tools, while secretly collecting sensitive wallet information during account import processes. Researchers said the extensions were designed to capture recovery phrases and private keys before sending the information to infrastructure controlled by the attackers.

According to Socket researcher Joseph Edwards, the identified extensions disguised themselves as wallet portals, desktop utilities, and browser-related tools. Their code was found to intercept recovery phrases and private keys entered during wallet import flows and attempt to transmit the collected information to attacker-controlled Cloudflare Workers. Four of the extensions were identified as clones of Rabby Wallet, while the remaining extensions were designed to imitate OKX Wallet. Researchers found that most of the identified add-ons communicated with the “*.icy-star-f45c.workers[.]dev” domain, which was used as part of the data collection process. The extensions identified in the campaign included fake versions of wallet-related tools as well as other browser utilities designed to appear legitimate. Researchers stated that the activity appears to continue an earlier campaign documented in August 2026, where similar malicious Firefox extensions were identified. The findings indicate that the operators behind the activity have continued changing package names, versions, extension identifiers, descriptions, and visual presentation while maintaining similar wallet interfaces, credential-handling methods, and network infrastructure.

As of October 5, 2026, all identified extensions had been removed from Mozilla Firefox. However, researchers advised users who installed any of the extensions and entered an actual recovery phrase or private key into the fake wallet interfaces to consider their wallets compromised. Users in such situations are recommended to create new wallets from a clean system and transfer their digital assets to protect them from potential unauthorized access. The discovery comes alongside several other reports involving suspicious browser extensions targeting users across Firefox, Google Chrome, and Microsoft Edge. Researchers have identified multiple campaigns where extensions presented themselves as productivity tools, privacy utilities, identity verification services, or cryptocurrency-related applications while carrying hidden functionality capable of collecting user information, monitoring browsing activity, or redirecting users to unsafe destinations.

Among the recently identified cases, researchers highlighted a Firefox extension called ID Pay that appeared to offer identity verification services before opening protected PDF files but contained functionality that could retrieve remote code and inject scripts into legitimate websites. Other campaigns involved clusters of browser extensions that collected browsing information, monitored user activity, redirected users to cryptocurrency-related pages, or attempted to obtain sensitive account information. Security researchers have also identified cases involving extensions marketed as VPN services, ad blockers, and AI-related tools that included capabilities beyond their advertised purpose. Some extensions were found collecting browser information, user interactions, or other sensitive data. These findings highlight the importance of carefully reviewing browser extensions before installation and regularly checking installed add-ons.

To reduce risks associated with malicious browser extensions, users are advised to review extensions installed on their browsers and remove tools that are unnecessary or unfamiliar. Organizations are also encouraged to audit browser extensions across managed environments, implement monitoring solutions, and use behavior-based security controls to identify suspicious extension activity. As browser-based threats continue to evolve, maintaining awareness and adopting stronger security practices remain important for protecting sensitive information and digital assets.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment