Supply-chain security firm Socket has identified a cluster of 16 malicious Firefox extensions that impersonated popular cryptocurrency wallets to steal recovery phrases and private keys during the wallet import process. Mozilla had unpublished all 16 from its add-on marketplace by October 5, according to Socket's October 7 report — but removal of the software does nothing for wallets whose secrets were already transmitted.

The campaign comprises four modified copies of Rabby Wallet, branded with the deceptive name "Raabby WaIIet," and twelve compact extensions built around OKX-derived interfaces presenting "Portal WALLET" onboarding screens, as GBHackers detailed. The Hacker News corroborated the findings, and Cybersecurity News reported that the fake onboarding flows turned familiar wallet import steps into traps.

Full Wallets as Camouflage

The Rabby clones are unusually elaborate: 1,114 files each, including working wallet keyrings, import screens, transaction interfaces and Webpack components, with official Rabby links and DeBank assets retained. That substantial legitimate functionality makes the malicious additions far less conspicuous than a bare phishing form.

Inside each clone's background script, an injected helper accepts 12-word or 24-word recovery phrases and 64-character hexadecimal private keys. The attackers inserted interception calls after legitimate operations such as importPrivateKey and createKeyringWithMnemonics — capturing the same secrets the wallet was accepting anyway, while allowing normal processing to continue so the user notices nothing.

The smaller "Portal WALLET" extensions take a simpler route: a React frontend validates exactly 12 or 24 words before dispatching a seed-phrase import message, which an active background handler transmits in full.

Secrets in URLs

All stolen values travel to attacker-controlled Cloudflare Workers — endpoints such as silent-wind-get.icy-star-f45c[.]workers[.]dev — with the raw secret embedded in the request parameters alongside a campaign marker, EQOx7EIPZSNi. Fifteen of the sixteen packages contain active collection handlers; one ships with implementation defects that break its theft workflow.

Two details stand out for defenders. Every malicious manifest declares Firefox data-collection permission as "none," directly contradicting the credential-transmission code packaged inside. And the code's comments claim only a hash and word count leave the device — while the payload explicitly includes the raw phrase, with hashing used merely for deduplication. Placing secrets in request URLs also risks secondary exposure through logging systems along the path.

Socket assesses with high confidence that this operation is a continuation of its August investigation, which tracked 77 related extensions — 40 confirmed malicious and 37 deceptive sports-score shells — sharing code, Worker infrastructure and the same campaign marker. No named operator has been identified.

What Affected Users Should Do Now

Anyone who entered a recovery phrase or private key into one of these extensions should treat that wallet as compromised regardless of whether funds have moved yet: remove the extension, generate a fresh wallet from a clean environment, and transfer assets immediately. Changing an extension password accomplishes nothing — it cannot invalidate an exposed seed phrase.

The structural lesson is broader. Browser extension stores remain a distribution channel where "published" reads as "vetted," and a permission manifest is self-attested by the uploader. Wallet users importing a seed phrase into any newly installed extension are handing over the keys to everything that phrase controls — the cheapest defense is never doing that without independent verification of the extension's origin.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.