Threat reportMalwareTL-2026-3088
Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto Recovery Phrases and Private Keys
Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto (TL-2026-3088), also tracked as Offside Wallet Theft Factory (linked August 2026 campaign), is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Mozilla Firefox (users who installed the malicious add-ons), maps to 8 MITRE ATT&CK techniques (T1036.005, T1056, T1071.001), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-3088
- Threat ID
- TL-2026-3088
- Also known as
- Offside Wallet Theft Factory (linked August 2026 campaign)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, cryptocurrency, consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 27
How Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto works
16 malicious Firefox extensions (4 Rabby Wallet clones and 12 OKX-style extensions) present fake wallet import screens that capture 12/24-word recovery phrases and 64-character hex private keys and send them to attacker-controlled Cloudflare Workers. Socket linked the campaign with high confidence to an August 2026 campaign (the 'Offside Wallet Theft Factory') through shared code, infrastructure and the tracking marker EQOx7EIPZSNi; Mozilla unpublished the extensions on October 5, 2026.
Socket researchers identified 16 malicious Firefox add-ons impersonating cryptocurrency wallets, split into two implementation groups. The Rabby family (4 extensions, 1,108 identical non-manifest files) clones the Rabby Wallet codebase and adds theft functions directly after the private-key and recovery-phrase import operations. The OKX family (12 extensions, 20 identical non-manifest files) is a small fake OKX-style wallet whose import form accepts only 12- or 24-word phrases and validates the word count before transmitting. The Rabby clones accept a 12-word phrase, a 24-word phrase or a 64-character hex private key (validation in the self._lv function). Users who install an extension and import an existing wallet hand their secrets to the attacker.
Exfiltration uses Cloudflare Workers. The Rabby clones send secrets in a GET request to silent-wind-get.icy-star-f45c.workers.dev with parameters w=<secret>, s=EQOx7EIPZSNi, k=login, a=<import|ui> and t=<timestamp>, which leaves raw secrets in proxy, DNS and URL logs. The OKX handlers use HTTPS POST with a JSON body {a, s, k, w}. One variant has a three-way fallback: navigator.sendBeacon (URL-encoded), fetch POST (mode no-cors, keepalive) and an image-pixel GET. Runtime message types include SEED_PHRASE_IMPORT and WALLET_SYNC. The Rabby clones keep legitimate upstream service URLs (api.rabby.io, static.debank.com), and the manifests declare data_collection_permissions.required = ["none"] while transmitting wallet data. One Worker domain, flat-wildflower-f954.fondationanimalaidrelief.workers.dev, belongs to a variant that is broken because its manifest does not register the background script. A misspelled branding string, 'Raabby WaIIet', is a detection pivot.
Socket attributes the 16 extensions to a single operator because of the identical campaign marker, reused Worker infrastructure (the icy-star-f45c namespace), consistent parameter schema and fixed payload code under varying packaging. The marker EQOx7EIPZSNi also appeared in Socket's August 2026 research on the 'Offside Wallet Theft Factory', a campaign of 77 linked Firefox extension identities (40 confirmed malicious) that impersonated OKX, Rabby and TronLink, used Supabase-controlled remote content switching, Cloudflare Pages phishing pages and a direct C2 IP (77.91.100.175), and modified Rabby's persistAllKeyrings() to leak serialized keyrings. No named threat actor or nation-state attribution is published. Mozilla unpublished the 16 extensions by October 5, 2026, and Socket published its findings on October 7, 2026. Users who already installed them remain exposed. Changing the extension password does not invalidate a stolen recovery phrase or private key, so affected wallets must be treated as permanently compromised and funds moved to a new wallet created on a clean device.
MITRE ATT&CK techniques used in TL-2026-3088
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation
Credential Access
Command and Control
Persistence
Execution
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto
- Mozilla — Firefox (users who installed the malicious add-ons)
Vulnerable versions: Any Firefox version with one of the 16 listed extension IDs installed
Fixed in: Extensions unpublished by Mozilla on 2026-10-05; installed copies must be removed manually - Rabby / OKX (impersonated brands) — Rabby Wallet and OKX Wallet
Vulnerable versions: Not vulnerable; brands are impersonated by fake extensions
Remediation for Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto
Immediate actions
- Remove any of the 16 listed Firefox extension IDs from all browser profiles and block those IDs via Firefox enterprise policy (ExtensionSettings)
- From a clean device, create a new wallet with a new recovery phrase, transfer assets, and revoke token approvals tied to the exposed wallet
- Treat every account derived from an exposed mnemonic or private key as compromised
- Block the listed workers.dev hostnames at DNS/proxy and search logs for the query parameter s=EQOx7EIPZSNi (redact field w)
- Preserve the original XPI files and browser profiles for analysis without running them on analyst workstations
Workarounds
- Changing the extension password does not invalidate a stolen recovery phrase or private key; rotate the wallet itself
Longer-term hardening
- Allow-list browser extensions in managed environments and inventory installed extensions regularly
- Hunt extension inventories for the four background.js hashes and the marker EQOx7EIPZSNi
- Monitor extension updates that change functionality sharply and combine permission review with code-similarity and infrastructure review
- Install wallet software only from the vendor's official site or verified store listing
Weaknesses (CWE) in Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto
Timeline of Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto
- Earliest Mozilla signing records for the linked 'Offside Wallet Theft Factory' extension cluster (Socket, August 2026 research).
- Latest Mozilla signing records for the linked August 2026 campaign cluster; the shared marker EQOx7EIPZSNi appeared in that research.
- Public reporting on rogue Firefox extensions hijacking crypto keyrings and clipboard data from the August campaign.
- Mozilla unpublished the 16 malicious Rabby and OKX clone extensions.
- Socket published its analysis of the 16 extensions (4 Rabby clones, 12 OKX-style) and linked them with high confidence to the August campaign.
- Cyber Security News reported the campaign, publishing extension IDs, Worker endpoints and file hashes.
Sources cited for Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto
- Hackers Use Fake Firefox Wallet Extensions to Steal Crypto Recovery Phrases
- Socket: Firefox Crypto Wallet Stealers (16 malicious Rabby/OKX clones)
- Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
- PiunikaWeb: Rogue Firefox extensions hijacking crypto keyrings, clipboard data
- Decrypt: Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
- CyberInsider: 40 Malicious Firefox Extensions Caught Stealing Crypto Wallet Data
Detection coverage for TL-2026-3088
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3088 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.