# Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto Recovery Phrases and Private Keys

> 16 malicious Firefox extensions (4 Rabby Wallet clones and 12 OKX-style extensions) present fake wallet import screens that capture 12/24-word recovery phrases and 64-character hex private keys and send them to attacker-controlled Cloudflare Workers. Socket linked the campaign with high confidence to an August 2026 campaign (the 'Offside Wallet Theft Factory') through shared code, infrastructure and the tracking marker EQOx7EIPZSNi; Mozilla unpublished the extensions on October 5, 2026.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3088
- **ID:** TL-2026-3088
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Socket researchers identified 16 malicious Firefox add-ons impersonating cryptocurrency wallets, split into two implementation groups. The Rabby family (4 extensions, 1,108 identical non-manifest files) clones the Rabby Wallet codebase and adds theft functions directly after the private-key and recovery-phrase import operations. The OKX family (12 extensions, 20 identical non-manifest files) is a small fake OKX-style wallet whose import form accepts only 12- or 24-word phrases and validates the word count before transmitting. The Rabby clones accept a 12-word phrase, a 24-word phrase or a 64-character hex private key (validation in the self._lv function). Users who install an extension and import an existing wallet hand their secrets to the attacker.

Exfiltration uses Cloudflare Workers. The Rabby clones send secrets in a GET request to silent-wind-get.icy-star-f45c.workers.dev with parameters w=<secret>, s=EQOx7EIPZSNi, k=login, a=<import|ui> and t=<timestamp>, which leaves raw secrets in proxy, DNS and URL logs. The OKX handlers use HTTPS POST with a JSON body {a, s, k, w}. One variant has a three-way fallback: navigator.sendBeacon (URL-encoded), fetch POST (mode no-cors, keepalive) and an image-pixel GET. Runtime message types include SEED_PHRASE_IMPORT and WALLET_SYNC. The Rabby clones keep legitimate upstream service URLs (api.rabby.io, static.debank.com), and the manifests declare data_collection_permissions.required = ["none"] while transmitting wallet data. One Worker domain, flat-wildflower-f954.fondationanimalaidrelief.workers.dev, belongs to a variant that is broken because its manifest does not register the background script. A misspelled branding string, 'Raabby WaIIet', is a detection pivot.

Socket attributes the 16 extensions to a single operator because of the identical campaign marker, reused Worker infrastructure (the icy-star-f45c namespace), consistent parameter schema and fixed payload code under varying packaging. The marker EQOx7EIPZSNi also appeared in Socket's August 2026 research on the 'Offside Wallet Theft Factory', a campaign of 77 linked Firefox extension identities (40 confirmed malicious) that impersonated OKX, Rabby and TronLink, used Supabase-controlled remote content switching, Cloudflare Pages phishing pages and a direct C2 IP (77.91.100.175), and modified Rabby's persistAllKeyrings() to leak serialized keyrings. No named threat actor or nation-state attribution is published. Mozilla unpublished the 16 extensions by October 5, 2026, and Socket published its findings on October 7, 2026. Users who already installed them remain exposed. Changing the extension password does not invalidate a stolen recovery phrase or private key, so affected wallets must be treated as permanently compromised and funds moved to a new wallet created on a clean device.

## MITRE ATT&CK

- T1583.007 Serverless
- T1204 User Execution
- T1176.001 Browser Extensions
- T1036.005 Match Legitimate Resource Name or Location
- T1684.001 Impersonation
- T1056 Input Capture
- T1071.001 Web Protocols
- T1567 Exfiltration Over Web Service

## Sources

- [Hackers Use Fake Firefox Wallet Extensions to Steal Crypto Recovery Phrases](https://cybersecuritynews.com/fake-firefox-wallet-extensions/)
- [Socket: Firefox Crypto Wallet Stealers (16 malicious Rabby/OKX clones)](https://socket.dev/blog/firefox-crypto-wallet-stealers)
- [Socket: 77 Firefox Extensions Linked to Crypto Wallet and Credential Theft](https://socket.dev/blog/firefox-crypto-wallet-theft)
- [PiunikaWeb: Rogue Firefox extensions hijacking crypto keyrings, clipboard data](https://piunikaweb.com/2026/08/20/rogue-firefox-extensions-hijacking-crypto-keyrings-clipboard-data/)
- [Decrypt: Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware](https://decrypt.co/376432/dozens-of-fake-firefox-wallet-extensions-linked-to-crypto-stealing-malware)
- [CyberInsider: 40 Malicious Firefox Extensions Caught Stealing Crypto Wallet Data](https://cyberinsider.com/40-malicious-firefox-extensions-caught-stealing-crypto-wallet-data/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3088
