Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malicious Mozilla Firefox Extensions Exploit Users' Cryptocurrency Wallet Recovery Phrases and Private Keys




In a recent development that has sent shockwaves through the cybersecurity community, a cluster of 16 malicious Mozilla Firefox extensions has been discovered that can steal cryptocurrency wallet recovery phrases and private keys from unsuspecting users. The extensions, which masquerade as legitimate browser tools and utilities, have been found to intercept recovery phrases and private keys during wallet import flows and send them to attacker-controlled Cloudflare Workers. Learn more about the threat and how to protect yourself.

  • Malicious Mozilla Firefox extensions have been discovered that can steal cryptocurrency wallet recovery phrases and private keys from unsuspecting users.
  • Four extensions are clones of Rabby Wallet, while the remaining 12 are targeted clones of OKX Wallet.
  • All identified extensions contact the "*.icy-star-f45c.workers[.]dev" domain, which is believed to be the end goal for the threat actors.
  • The threat actors are rotating package names, versions, extension IDs, descriptions, and the presentation layer, while reusing the same wallet interfaces, credential-handling logic, and network infrastructure.
  • Users who installed the malicious extensions and entered a real recovery phrase or private key should assume compromise and take action to secure their assets.
  • The discovery highlights the importance of regular browser extension reviews and the need for users to be cautious when installing new browser tools and utilities.
  • Cloudflare Workers is being used as a conduit for malicious activity, emphasizing the need for cloud security measures to be taken seriously.
  • The threat actors are using AI-powered tools to accelerate reconnaissance, compromise identities, and escalate access, highlighting the growing threat of AI-powered attacks.



  • In a recent development that has sent shockwaves through the cybersecurity community, a cluster of 16 malicious Mozilla Firefox extensions has been discovered that can steal cryptocurrency wallet recovery phrases and private keys from unsuspecting users. The extensions, which masquerade as legitimate browser tools and utilities, have been found to intercept recovery phrases and private keys during wallet import flows and send them to attacker-controlled Cloudflare Workers.

    According to cybersecurity researcher Joseph Edwards, the extensions' code is capable of intercepting recovery phrases and private keys and sending them to attacker-controlled Cloudflare Workers. The extensions' names, which are listed below, include view-focus-bright@webtools.co@6.12.2, quick-track-nest@tabtools.co@8.1.18, vibe-kit-tool@fasttools.co@9.21.9, and edge-hub-snap@protools.net@4.12.24, among others.

    Four of the extensions have been identified as clones of Rabby Wallet, while the remaining 12 extensions are targeted clones of OKX Wallet. All of the identified extensions, except for one, have been found to contact the "*.icy-star-f45c.workers[.]dev" domain, which is believed to be the end goal for the threat actors. The end goal is to collect mnemonic phrases and private keys and exfiltrate them to the Cloudflare Workers domain.

    The activity is assessed to be a continuation of an earlier wave of malicious Firefox extensions that were documented by an application security company in August 2026. The findings suggest that the threat actors are rotating package names, versions, extension IDs, descriptions, and the presentation layer, while reusing the same wallet interfaces, credential-handling logic, and network infrastructure.

    As of October 5, 2026, all of the extensions have been removed from the Chrome Web Store. However, users who have installed any of the malicious extensions and entered a real recovery phrase or private key into the fake wallet interfaces should assume compromise. They are advised to create a new wallet from a clean system and move their assets to a secure location.

    The discovery of these malicious extensions highlights the importance of regular browser extension reviews and the need for users to be cautious when installing new browser tools and utilities. Organizations are also advised to audit extensions within managed environments, adopt runtime monitoring approaches, and deploy behavior-based extension monitoring technologies to detect suspicious activity.

    Furthermore, the threat actors' use of Cloudflare Workers to exfiltrate stolen data highlights the need for cloud security measures to be taken seriously. Cloudflare Workers is a cloud-based platform that allows developers to run JavaScript code on the cloud, but it can also be used as a conduit for malicious activity.

    In recent months, there have been several other malicious browser extensions discovered that have masqueraded as legitimate productivity utilities, privacy utilities, and cryptocurrency-related services. These extensions have been used to harvest data, monitor user browsing habits, and stealthily replace the active tab with a destination URL specified in a remotely-retrieved configuration.

    The campaign is attributed to a Korean-speaking threat actor, and it has been active since March 2025. The threat actor's use of AI-powered tools to accelerate reconnaissance, compromise identities, and escalate access highlights the growing threat of AI-powered attacks.

    In response to the threat, security teams are advised to focus on runtime identity controls, and to implement measures to detect and prevent AI-powered attacks. The need for runtime identity controls is critical, as AI agents are already operating inside enterprises with growing access to sensitive systems and data.

    The recent discovery of these malicious Mozilla Firefox extensions serves as a reminder of the importance of staying vigilant in the face of emerging threats. It is essential for users and organizations to stay informed about the latest threats and to take proactive measures to protect themselves against malicious activity.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malicious-Mozilla-Firefox-Extensions-Exploit-Users-Cryptocurrency-Wallet-Recovery-Phrases-and-Private-Keys-ehn.shtml

  • https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html


  • Published: Thu Oct 8 06:20:09 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us