Malicious Firefox Extensions

Overview

Sixteen malicious Firefox extensions masquerading as cryptocurrency wallets, browser utilities and desktop tools have been discovered stealing wallet recovery phrases and private keys. The campaign targeted users of Rabby and OKX Wallet through convincing cloned interfaces. Once a victim entered a recovery phrase or private key, the extension intercepted the secret and attempted to send it to attacker-controlled infrastructure hosted through Cloudflare Workers. The extensions have since been removed, but the incident highlights a broader problem: the browser has become an increasingly powerful execution environment, and every installed extension becomes part of its security boundary.

The Extension Does Not Have to Look Malicious

Four of the identified extensions were clones of Rabby Wallet, while twelve targeted OKX Wallet users. The operators changed extension names, versions, identifiers and presentation while retaining common code, credential-handling logic and infrastructure. This is a familiar supply-chain technique. Instead of attacking the legitimate wallet directly, the attacker creates a counterfeit component that the victim voluntarily installs. The malicious extension can then operate inside the trusted browser environment. In the Rabby variants, wallet import and key-management functions were modified so recovery phrases and private keys could be intercepted during legitimate wallet operations. The OKX variants similarly presented recovery-phrase import workflows designed to capture the secret. The attack therefore does not require the victim to visit an obviously malicious website. The malicious application is already sitting inside the trusted browser.

A Recovery Phrase Is More Valuable Than a Password

The severity of this campaign comes from what is being stolen. A password can often be reset. A recovery phrase is fundamentally different. It can provide the information required to recreate a cryptocurrency wallet and control its associated assets from another device. Once a recovery phrase or private key has been exposed, simply removing the malicious extension does not restore security. Socket found that the campaign reused infrastructure and code across multiple extensions, including Cloudflare Worker endpoints used to receive stolen wallet secrets. The same campaign also appears to be a continuation of earlier malicious Firefox-extension activity.

Low Permissions Do Not Automatically Mean Low Risk

One particularly important lesson is that extension permissions alone are not sufficient to establish whether an extension is trustworthy. A malicious extension can obtain highly sensitive information through the functionality it controls rather than through obviously excessive browser permissions. A counterfeit wallet interface simply asks the user to enter the recovery phrase as part of an apparently legitimate workflow. This creates a difficult security boundary. The user believes the secret is being supplied to a wallet, while the browser extension can capture it before the legitimate wallet process receives it. Organisations managing browsers therefore need to consider what extensions do, not merely what permissions they request.

Browser Extensions Need Supply-Chain Governance

Enterprise browser environments should maintain an approved extension inventory and prevent users from installing arbitrary add-ons where practical. Existing extensions should be reviewed regularly, particularly those handling authentication, payments, cryptocurrency, productivity data or access to corporate systems. Extension updates also deserve scrutiny. A previously legitimate extension can become malicious through a compromised update or a repackaged version. Behaviour-based monitoring can provide another layer of defence by identifying extensions that unexpectedly communicate with external infrastructure, manipulate sensitive workflows or transmit information that does not match their stated purpose.

Expert in the Cloud Insight

The browser is increasingly becoming an application platform rather than simply a window into the internet. Extensions can read content, interact with websites, access browser functionality and modify application behaviour. That makes extension management part of endpoint security and, increasingly, part of software supply-chain security. The Firefox campaign demonstrates the danger of allowing a trusted browser component to become an untrusted intermediary between the user and a critical application. The most dangerous extension may not be the one asking for the most permissions; it may be the one quietly receiving the most valuable information.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.