16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
A cluster of 16 malicious Firefox extensions, posing as wallet portals and OKX Wallet clones, have been discovered. These extensions steal cryptocurrency wallet recovery phrases and private keys by intercepting wallet import flows and sending secrets to attacker-controlled Cloudflare Workers. The activity is a continuation of a previous campaign and involves rotating package names and versions while reusing wallet interfaces. Users who installed any of these extensions and entered recovery phrases should assume compromise and create a new wallet. Organizations should audit extensions and deploy runtime monitoring technologies.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
