Cybersecurity researchers have discovered a group of 16 malicious Mozilla Firefox extensions designed to steal cryptocurrency wallet recovery phrases and private keys.

According to Socket researcher Joseph Edwards, the extensions disguise themselves as wallet portals, desktop utilities, and browser tools. Their malicious code intercepts recovery phrases and private keys when users import wallets and attempts to send the stolen information to attacker-controlled Cloudflare Workers.

The 16 malicious Firefox extensions identified by researchers are:

Four of the extensions are clones of Rabby Wallet, while the others imitate OKX Wallet. Researchers found that all but one of the identified extensions contacted a domain hosted through Cloudflare Workers. The infrastructure was used to collect wallet recovery phrases and private keys and send them to the attackers.

The campaign appears to be a continuation of an earlier wave documented in August 2026. Researchers said the attackers are changing package names, versions, extension IDs, descriptions, and the visual presentation of the extensions while continuing to reuse the same wallet interfaces, credential-stealing logic, and network infrastructure.

This approach allows the attackers to repeatedly publish new versions or differently named extensions while maintaining much of the underlying malicious code.

As of October 5, 2026, all 16 extensions had been removed. However, removal from the Firefox extension store does not protect users who had already installed them and entered sensitive wallet information.

READ
Critical Dell System Update Flaw Lets Attackers Gain Root Access

Anyone who entered a genuine cryptocurrency recovery phrase or private key into one of these fake wallet interfaces should assume that the wallet credentials have been compromised. Security researchers recommend creating a new wallet from a clean system and moving remaining assets to the new wallet.

The discovery is part of a broader increase in malicious browser extensions targeting users of Firefox, Chrome, and Microsoft Edge. Security researchers have recently uncovered extensions disguised as productivity tools, VPNs, privacy utilities, cryptocurrency services, identity verification tools, and ad blockers.

One Firefox extension, for example, was found posing as an identity verification utility for opening protected PDF documents while containing functionality capable of retrieving a remote payload and injecting JavaScript into the legitimate Google Accounts website to steal session cookies.

Researchers have also identified dozens of Chrome and Edge extensions that appear to be legitimate productivity tools but secretly collect browsing information, monitor user activity, or redirect users to websites controlled by attackers.

Other campaigns have focused specifically on cryptocurrency users by disguising malicious extensions as wallet-related services or tools associated with well-known financial personalities. These extensions can redirect victims to fake cryptocurrency wallet pages designed to capture recovery phrases.

VPN-themed extensions have also been abused. Some malicious or questionable extensions advertised as VPNs for accessing blocked services have been found routing browser traffic through proxy infrastructure controlled or configured by third parties.

Another area of concern is the growing number of extensions capable of accessing AI chatbot conversations. Researchers have found browser extensions that can intercept conversations from services including ChatGPT, Gemini, Claude, Perplexity, Character.AI, and GitHub Copilot.

READ
U.S. Offers $10 Million Reward for Chinese Hacker Accused of Targeting COVID Research

Some extensions have also used remote command functionality to collect browser fingerprints, browsing history, social media information, and other sensitive data while attempting to bypass browser security restrictions.

The growing number of malicious extensions highlights the risks of installing browser add-ons simply because they appear legitimate or have convincing names and descriptions. Extensions can receive powerful permissions that allow them to access websites, read or modify page content, and potentially interact with sensitive information.

Users should regularly review the extensions installed in Firefox, Chrome, Edge, and other browsers and remove anything they no longer need or do not recognize. Cryptocurrency users should be especially careful when an extension asks them to enter a wallet recovery phrase or private key.


Buy ExpressVPN with PayPal or Credit Card

Organizations should also audit browser extensions installed across managed devices and consider using runtime and behavior-based monitoring to detect suspicious extensions and unusual data transfers.

Advertisement