Build1 publisherNot yet confirmed elsewhere3 min readPublished
Sixteen Firefox extensions cloned Rabby and OKX wallets to capture seed phrases at import
Socket found 16 Firefox extensions posing as Rabby and OKX wallets that intercept recovery phrases and private keys during wallet import. Names and IDs rotated behind a screen that still read Rabby Wallet, so only an allowlist of exact extension IDs holds up.
The Engineer · Build desk

What happened
- Four of the extensions repackage Rabby Wallet as "Raabby WaIIet" and send the raw seed or private key to a Cloudflare Worker in GET query parameters.
- Eleven of the twelve OKX Wallet clones run a background script that takes a 12- or 24-word phrase and forwards it to a Cloudflare Worker.
- Every manifest declared Firefox's data collection permission as none, although the code handles and transmits wallet recovery material.
- Mozilla had unpublished the malicious extensions as of October 5, according to Socket.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Screening wallet extensions by name cannot catch this campaign, so teams that allow browser wallets need an allowlist pinned to the exact extension ID they approved.
- constraint Firefox's self-declared data collection field is no longer a usable screening signal for wallet extensions after all 16 packages set it falsely.
- cost Victims carry the whole recovery cost: a new wallet built in a clean environment and every asset moved, whatever Mozilla does with the listings.
- precedent With Socket linking this batch to its August 2026 findings, the October takedown is one round in a recurring campaign, and the reused icy-star-f45c host is the indicator to block.
Socket describes the Rabby clones as complete wallet applications. Each package holds 1,114 files and a Webpack build tagged webpackChunkrabby, with Rabby's locale material, keyring code, import screens and transaction UI [12]. Links to Rabby's official Chrome Web Store listing, its legal pages and its mobile apps survive in the clone [15]. Interception happens at one step, when a user enters a recovery phrase or private key into an import screen [1].
Its rebrand is uneven. On the onboarding screen it still says "Rabby Wallet", while the document title says Raabby WaIIet and the manifest lists the author as Debrunk [14]. That fake name adds an a to Rabby and puts capital I's where Wallet has l's, across index.html, desktop.html, locale names and document titles [13]. The operators applied their typo more consistently than anything else in the package, and Socket says that consistency gives defenders a static detection string [13].
A check on the name fails for both user and reviewer. A user sees "Rabby Wallet" on the first screen [14]. Someone reviewing the listing has to spot one extra letter and two swapped glyphs [13]. Between uploads, the operators rotate package names, versions, extension IDs, descriptions and presentation, while reusing the same interfaces, credential-handling logic, campaign marker and servers [7].
Publisher identity is where the clones stop matching. The 16 IDs sit under nine domains, including webtools.co, browserweb.com and plugify.example [20]. A blocklist of those domains would need an update at each new upload. I think the control that holds up is an allowlist: the managed browser installs the exact extension ID a team approved for its wallet and refuses everything else. It depends on the team recording the vendor's real extension ID at the moment it approves the wallet.
Socket splits the OKX family into three background-script variants, and one never worked [18]. The package sipoo-grozza@browserweb.com carries exfiltration code, but its manifest does not load background.js, and its frontend sends SEED_PHRASE_IMPORT while the background handles only WALLET_SYNC [4]. It also reports to a different host, fondationanimalaidrelief[.]workers[.]dev. The other 15 contact icy-star-f45c[.]workers[.]dev [5]. So 15 working stealers shared one exfiltration host [19].
Citing reused infrastructure, tactics and targeted lures, Socket wrote: "we assess with high confidence that this campaign is a continuation of crypto-theft targeted extensions Socket identified in August 2026" [8].
Both impersonated wallets are large. Socket puts Rabby at 900,000 Chrome Web Store users and 500,000 Google Play downloads, and OKX at more than 1,000,000 Chrome Web Store users [16]. For anyone who typed a real phrase into a working variant, Socket's note is direct: "Changing only the extension password does not revoke a stolen seed phrase or private key" [11].
What to watch
- New Raabby WaIIet or OKX lookalikes appearing on Firefox under fresh IDs that still call icy-star-f45c[.]workers[.]dev.
- Any change by Mozilla to how it checks the self-declared data collection permission on extensions that handle wallet secrets.
- Rabby or OKX publishing their genuine Firefox extension IDs so administrators can pin an allowlist to them.