Yaamlabs

Threat intel

16 fake Rabby and OKX add-ons stole Firefox seed phrases

Socket found 16 Firefox add-ons cloning Rabby and OKX wallets that send recovery phrases to Cloudflare Workers. How to find them, block them and recover.

Sixteen Firefox add-ons posing as the Rabby and OKX crypto wallets captured the recovery phrases and private keys people typed in while importing a wallet, and sent them to servers the attackers ran on Cloudflare Workers. Socket Threat Research, in a report by Joseph Edwards published on October 7, 2026, found four of them built from Rabby Wallet's own code and twelve with an interface modelled on OKX Wallet. Mozilla had unpublished all sixteen from the Firefox add-ons site by October 5.

Removal from the store protects nobody who already used one. A recovery phrase (the 12 or 24 words that regenerate every key in a wallet) cannot be changed, so whoever has it controls the funds until they are moved. If anyone in your organisation keeps company or treasury crypto in a browser wallet on Firefox, check their profiles today. Socket assesses with high confidence that this batch continues the campaign it reported in August, when it confirmed 40 malicious Firefox add-ons out of 77 linked extension identities.

How it works

A wallet extension normally takes the recovery phrase or private key once, during import, encrypts it with the user's password and stores it locally. That moment is the only time the secret passes through the extension in plain form, and it is where these add-ons attach their code.

The four Rabby clones are repackaged copies of the real Rabby Wallet, around 1,100 files each, partly rebranded as "Raabby WaIIet" with capital I's in place of the l's. The wallet works normally. Socket found extra code that runs right after the legitimate import and keyring creation steps: it accepts only a 12 word phrase, a 24 word phrase or a 64 character hex private key, removes duplicates, and sends the secret to a Cloudflare Workers host in the query string of a GET request. Because the victim gets a working wallet, nothing looks wrong.

The twelve OKX-style add-ons are small packages that show a "Portal WALLET" import screen with OKX-like branding. The page checks that the phrase is exactly 12 or 24 words and passes it to the background script, which posts it over HTTPS to the attackers. One variant tries three ways in turn: a browser beacon, a fetch request and an image request. Its code comments claim that only a hash and the word count leave the device; the code sends the full phrase. One package, sipoo-grozza@browserweb.com, never worked, because its manifest does not load its background script. The theft code is still in it.

Every one of the sixteen manifests declares that the add-on collects no data, so a user who checked the listing before installing saw nothing to worry about.

What attackers are doing

The add-ons were presented as wallet portals, desktop utilities and browser tools. Fifteen of the sixteen send stolen secrets to hosts under one Cloudflare Workers account, icy-star-f45c.workers[.]dev. Socket links the batch to the August wave through that infrastructure, the theft code and a campaign marker embedded across the packages. According to Socket, the operators keep changing package names, versions, extension IDs and descriptions while reusing the same wallet screens, theft logic and servers, so expect the next batch to look different.

Neither Socket nor the press coverage gives install counts, victim numbers or losses, and the activity has not been attributed to a known group. The products being imitated are large: Rabby has about 900,000 users on the Chrome Web Store and OKX Wallet more than a million.

What to do

1. Find the add-ons

On a single machine, open about:support and scroll to the Add-ons table, which lists every extension in that profile with its name, version, enabled state and ID. Match the IDs, not the names, because the names were changed often. The sixteen IDs are:

view-focus-bright@webtools.co, quick-track-nest@tabtools.co, vibe-kit-tool@fasttools.co, edge-hub-snap@protools.net, core-hub-peak@neattools.example, sipoo-grozza@browserweb.com, mozart-seo@webtools.com, clean-file-bar@neattools.com, clean-net-timer@plugify.example, manager-square@webtools.com, manager-course@webtools.com, val-andrew@browserweb.com, manager-team@browserweb.com, valory-andrew@browserweb.com, franklin-uk@browserweb.com, franklin-uro@browserweb.com.

Across a fleet, search Firefox profile folders for those IDs. Each installed add-on sits in the profile's extensions folder as <ID>.xpi, and the profile's extensions.json lists them all. On Windows, profiles live under %APPDATA%\Mozilla\Firefox\Profiles\. Check every profile on the machine and every device signed into the same Firefox account, since Socket points out that synced extension state can bring an add-on back. Socket's report also gives SHA-256 hashes of each XPI file for endpoint tools that scan by hash.

2. Block them, and then block by default

Firefox's ExtensionSettings enterprise policy, set through Group Policy, a macOS configuration profile or a policies.json file in the distribution folder next to the Firefox program, controls which add-ons can exist. An entry with "installation_mode": "blocked" for an extension ID stops it being installed and removes it if it already is. A "*" entry set to blocked, with allowed or force_installed entries for the add-ons you approve, turns the browser into an allowlist; blocked_install_message on the "*" entry tells users who to ask. Open about:policies on a test machine to confirm the policy loaded without errors. Blocking by ID only stops these sixteen; since the operators rename and re-upload, only the allowlist covers the next batch.

3. Hunt the network side

Search DNS and web proxy logs back to March 2026, when the earlier wave began, for any subdomain of icy-star-f45c.workers[.]dev. A hit means a working variant ran and probably sent a secret. On the Rabby clones the secret is in the URL itself, in the w parameter, so redact it before copying log lines into tickets or chat.

4. If a recovery phrase or private key was entered

Treat the wallet as owned by someone else and act in this order:

  1. Remove the add-on and stop using that browser profile for anything involving the wallet.
  2. On a clean device, create a new wallet with a new recovery phrase. Do not import the old phrase anywhere.
  3. Move all assets to the new wallet straight away, highest value first, because the attacker can sweep the same addresses at any time.
  4. Revoke token approvals granted from the old addresses, using your wallet's approval view or a block explorer's token approval checker.
  5. Treat every account derived from the exposed phrase as compromised, on every chain. If it was a hardware wallet's phrase, the hardware wallet is exposed too.

Changing the extension's password does nothing here: it only protects the local encrypted copy, and the attacker already has the phrase.

The wider lesson

Browser extensions get less scrutiny than installed software even though a wallet extension holds keys to real money. These add-ons went through store review, declared that they collected nothing, and in the Rabby case worked exactly like the real product. An extension allowlist enforced through policy, plus a rule that wallets are installed only from the link on the vendor's own site, would have kept all sixteen off managed machines.

Our safeguarding and hardening work includes browser policy baselines such as extension allowlists, and our security operations team can run the profile and DNS hunts above across your endpoints. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Socket Threat Research, The Hacker News, CyberInsider, PiunikaWeb, Socket, August 2026 campaign, Mozilla ExtensionSettings policy reference.

Back to the blog, or read this post on the full site.