Full Report
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to
Analysis Summary
# Tool/Technique: Malicious Firefox Crypto-Stealer Extensions
## Overview
A cluster of 16 malicious Mozilla Firefox extensions designed to harvest sensitive cryptocurrency information. These extensions masquerade as legitimate wallet portals (specifically Rabby and OKX clones) or benign browser utilities. Their primary purpose is to intercept mnemonic recovery phrases and private keys during the wallet import process and exfiltrate them to attacker-controlled infrastructure.
## Technical Details
- **Type:** Malware / Info-Stealer
- **Platform:** Mozilla Firefox (Web Browser)
- **Capabilities:** Credential harvesting, UI impersonation, data exfiltration.
- **First Seen:** Reported October 2026 (continuation of a wave first seen August 2026).
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- **[T1176 - Browser Extensions]**: Use of malicious extensions to gain a foothold in the user's browser environment.
- **[TA0006 - Credential Access]**
- **[T1056.001 - Input Capture: Keylogging]**: Intercepting recovery phrases as they are typed into fake forms.
- **[T1601 - Adversary-in-the-Browser]**: Modifying or intercepting web traffic/inputs within the browser context.
- **[TA0010 - Exfiltration]**
- **[T1041 - Exfiltration Over C2 Channel]**: Sending stolen secrets to Cloudflare Workers.
## Functionality
### Core Capabilities
- **Impersonation:** Clones the user interfaces of popular hardware and software wallets (Rabby Wallet, OKX Wallet) to trick users into entering sensitive data.
- **Credential Interception:** Hooks into the "wallet import" flow to capture mnemonic phrases and private keys in real-time.
- **Exfiltration:** Utilizes Cloudflare Workers as a backend to receive stolen data, making the traffic appear legitimate to many basic network filters.
### Advanced Features
- **Infrastructure Rotation:** The actors rotate package names, extension IDs, and version numbers while maintaining the same core credential-handling logic to evade static detection.
- **Strategic Disguise:** Beyond wallet clones, some variants pose as "desktop utilities" or "SEO tools" to broaden the target demographic.
## Indicators of Compromise
### File Names (Extension IDs/IDs)
- `[email protected]@6.12.2`
- `[email protected]@8.1.18`
- `[email protected]@9.21.9`
- `[email protected]@4.12.24`
- `[email protected]@8.24.21`
- `[email protected]@2.1`
- `[email protected]@1.4`
- `[email protected]@4.21.8`
- `[email protected]@4.17.1`
- `[email protected]@1.4`
- `[email protected]@1.4`
- `[email protected]@1.4`
- `[email protected]@1.4`
- `[email protected]@1.4`
- `[email protected]@1.4`
- `[email protected]@1.4`
### Network Indicators
- `*.icy-star-f45c.workers[.]dev` (Primary exfiltration C2)
## Associated Threat Actors
- **Unknown:** Assessed to be a persistent actor/group specializing in cryptocurrency theft, previously active in August 2026.
## Detection Methods
- **Signature-based detection:** Monitoring for the specific Extension IDs and metadata associated with the malicious packages.
- **Behavioral detection:** Identifying browser extensions that attempt to send POST requests containing sensitive keywords (e.g., "mnemonic," "private_key") to unauthorized Cloudflare Workers or third-party domains.
- **Audit:** Reviewing the `manifest.json` of installed extensions for suspicious permissions or unexpected background scripts.
## Mitigation Strategies
- **Prevention:** Install extensions only from verified developers and official stores; verify extension permissions upon installation.
- **Hardening:** Use hardware wallets for signing transactions where the private key never leaves the physical device, rendering browser-based interception ineffective.
- **Incident Response:** If compromised, users must immediately move funds to a new wallet generated on a clean system with a new recovery phrase.
## Related Tools/Techniques
- **ID-Pay:** A similar Firefox extension targeting Google session cookies.
- **Phishing-as-a-Service (PhaaS):** Similar techniques used to redirect users to fake crypto-utility pages.