Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys.
"The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers," Socket researcher Joseph Edwards said in an analysis.
The names of the extensions are below -
- [email protected]@6.12.2
- [email protected]@8.1.18
- [email protected]@9.21.9
- [email protected]@4.12.24
- [email protected]@8.24.21
- [email protected]@2.1
- [email protected]@1.4
- [email protected]@4.21.8
- [email protected]@4.17.1
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
- [email protected]@1.4
Four of these extensions are clones of Rabby Wallet, while the rest are targeted clones of OKX Wallet. All the identified add-ons barring one have been found to contact the "*.icy-star-f45c.workers[.]dev" domain. The end goal is to collect mnemonic phrases and private keys and exfiltrate them to the Cloudflare Workers domain.
The activity is assessed to be a continuation of an earlier wave that the application security company documented in August 2026. The findings suggest that the threat actors are rotating package names, versions, extension IDs, descriptions, and the presentation layer, while reusing the same wallet interfaces, credential-handling logic, and network infrastructure.
As of October 5, 2026, all the extensions have been removed. Users who have installed any of the aforementioned extensions and entered a real recovery phrase or private key into the fake wallet interfaces should assume compromise, create a new wallet from a clean system, and move their assets.
The findings coincide with the discovery of several malicious or sketchy extensions for Firefox, Google Chrome, and Microsoft Edge in recent months -
- A Firefox extension called "ID- Pay" ([email protected]) that poses as a utility for identity verification before opening protected PDF documents, but harbors functionality to fetch a remote payload from attacker-controlled infrastructure and inject JavaScript into the legitimate "accounts.google[.]com" domain to steal session cookies.
- A cluster of 32 malicious browser extensions across the Chrome Web Store and Microsoft Edge Add-ons Store that masquerades as benign productivity utilities, but harvest data, monitor user browsing habits, and stealthily replace the active tab with a destination URL specified in a remotely-retrieved configuration. The campaign has been active since March 2025 and attributed to a Korean-speaking threat actor.
- A cluster of about 30 malicious browser extensions that masquerade as productivity tools, privacy utilities, and cryptocurrency-related services published under the names of legitimate, high-profile financial personalities with the goal of redirecting victims to cryptocurrency wallet phishing pages designed to steal recovery phrases, while skipping English-speaking users and analysis environments.
- A cluster of 31 Russian-language Chrome extensions that are advertised as VPNs for a specific blocked service in the country (e.g., Anthropic Claude, Facebook, Google Gemini, LinkedIn, Netflix, Notion, OpenAI ChatGPT, Spotify, Telegram, Threads, Wikipedia, X, and YouTube) but routes browser traffic through a proxy whose server list is fetched from a GitHub Pages URL (or Blogger, Google Docs, and Telegram for redundancy) post-installation.
- A Chrome Web Store extension named Stylish that intercepts every ChatGPT, Gemini, Claude, Perplexity, Character.AI, and GitHub Copilot conversation and forwards the full response text to its operator.
- A Chrome Web Store extension named "Urban VPN" that includes an "anti-phishing" feature designed to warn users before visiting any harmful sites, but never returns a phishing warning and silently transmits visited URLs to servers operated by BIScience. Urban VPN was previously accused of capturing user conversations with AI chatbots. However, the extension developers clarified that AI-related processing only occurs after the "AI Protection" feature was explicitly enabled. Earlier this May, the add-on developers also addressed a high-severity security vulnerability that allowed any website to send arbitrary commands to the extension without origin verification.
- A Chrome Web Store extension named "Pop up blocker for Chrome™ - Poper Blocker" that's marketed as an ad blocker but ships an interpreter that downloads and interprets instructions from a command-and-control (C2) server, circumventing Google's Manifest V3 rules banning this behavior. The commands allow it to collect browser fingerprints, browsing history, social media profile information, and AI chatbot interactions.
To counter the threat associated with malicious extensions, users are advised to review the browser extensions installed in their environment, and remove those that are no longer needed. Organizations are recommended to audit extensions within managed environments, adopt runtime monitoring approaches, and deploy behavior-based extension monitoring technologies to detect suspicious activity.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.










English (US) ·