Cybersecurity researchers have uncovered 16 malicious Mozilla Firefox extensions designed to steal cryptocurrency wallet recovery phrases and private keys from unsuspecting users. The discovery, documented by application security firm Socket in October 2026, reveals that the extensions posed as wallet portals, desktop utilities, and browser tools while secretly intercepting sensitive credentials. According to researcher Joseph Edwards, the malicious code captured recovery phrases and private keys during wallet import processes and attempted to transmit those secrets to infrastructure controlled by attackers using Cloudflare Workers.

The extensions masqueraded as legitimate cryptocurrency tools, with four clones imitating Rabby Wallet and the remainder targeting OKX Wallet users. All but one of the identified add-ons connected to the domain "*.icy-star-f45c.workers[.]dev" to exfiltrate stolen credentials. The complete list includes extensions with names like view-focus-bright@webtools.co@6.12.2, quick-track-nest@tabtools.co@8.1.18, and sipoo-grozza@browserweb.com@2.1, among others. Mozilla removed all 16 extensions from its platform as of October 5, 2026. Socket's analysis determined this activity continues an earlier campaign the company had documented in August 2026, with threat actors rotating package names, versions, extension IDs, descriptions, and visual presentation while maintaining the same wallet interfaces, credential-handling mechanisms, and network infrastructure.

The report characterizes the campaign as part of a broader pattern of malicious browser extensions targeting users across Firefox, Google Chrome, and Microsoft Edge in recent months. Socket's findings note that anyone who installed the compromised extensions and entered genuine recovery phrases or private keys into the fraudulent wallet interfaces should presume their credentials are compromised. According to Edwards, victims need to generate a new wallet from an uncompromised system and transfer their digital assets immediately. The report documents similar threats including a Firefox extension called "ID-Pay" that steals Google session cookies, a cluster of 32 malicious extensions attributed to a Korean-speaking threat actor active since March 2025, and roughly 30 extensions impersonating legitimate financial personalities to redirect victims to phishing pages designed to capture recovery phrases.

Socket's analysis explains that threat actors are exploiting user trust in browser extension ecosystems by continuously adapting their tactics while reusing core infrastructure. The report details how attackers maintain operational persistence by changing superficial elements like names and descriptions while keeping the underlying credential-theft logic and exfiltration endpoints constant. This approach allows malicious actors to evade detection even after previous campaigns are exposed and removed. The report recommends that users review all browser extensions currently installed in their environments and remove those no longer necessary. Organizations should audit extensions within managed systems, implement runtime monitoring approaches, and deploy behavior-based extension monitoring technologies to identify suspicious activity before credentials are compromised. For cryptocurrency holders especially, the stakes of a single careless installation can mean total asset loss, making vigilance around browser add-ons a fundamental security practice rather than an optional precaution. As extension marketplaces struggle to keep pace with sophisticated social engineering tactics, the burden of verification increasingly falls on end users who may lack the technical expertise to distinguish authentic tools from convincing counterfeits.