Rabby Clone Interface
At a Glance
| Malware family | Fake wallet extensions in two families: Rabby clones and OKX clones |
| Threat actor | Unnamed; linked with high confidence to an August 2026 Socket campaign |
| Targets | Firefox users importing crypto wallets; victim counts not disclosed |
| Delivery vector | Malicious listings on Mozilla’s Firefox add-ons store |
| Key capabilities | Theft of 12- and 24-word recovery phrases and private keys |
| Sources | Socket Threat Research; Koi Security via Dataconomy |
TL;DR
Sixteen Firefox extensions posed as Rabby and OKX wallets. When users imported a wallet, the extensions copied the recovery phrase or private key and sent it to Cloudflare Workers. Mozilla has pulled them, but anyone who typed in a real phrase should move their funds.
Delivery
The extensions sat on Mozilla’s official add-ons store. Four were full clones of Rabby Wallet with a misspelled brand. The other 12 posed as a “Portal WALLET” that closely resembled OKX Wallet. Some even linked to real Rabby and OKX help pages to look legitimate.
Notably, every manifest told Firefox the add-on collected no data. That claim contradicts code that “handles and transmits wallet recovery material,” Socket notes.
Infection Chain
The Rabby Clones
The Rabby copies kept the real wallet working. However, the attackers inserted hooks right after key import steps. Each hook accepted only a 12- or 24-word phrase or a 64-character private key. As a result, the attacker received “the same secret the wallet accepts, while leaving the underlying wallet flow intact.”
These clones also requested very broad access, including script injection into every page. Socket calls this excessive access but found no proof of wider browsing theft.
The OKX Clones
The smaller extensions opened a popup asking users to import a recovery phrase. A background script then grabbed the 12 or 24 words. One version included comments claiming only a hash left the device. Yet the code sent the raw phrase. Socket calls this “direct evidence of concealment rather than benign analytics.” One extension was broken as shipped, but still held working theft code.
Command-and-Control and Data Exfiltration
All 16 extensions sent secrets to Cloudflare Workers. The Rabby clones put the raw phrase directly in a web address. That exposes it to any server or log that records the URL. The OKX clones used POST requests. One variant added backup methods, including a tracking-pixel fallback.
Attribution
Socket does not name the operators. However, it links this wave “with high confidence” to a campaign it exposed in August 2026. That earlier wave involved 40 Firefox extensions. Both share a campaign marker, infrastructure, and lures.
Fake wallet add-ons on Firefox are not new. In August 2025, Koi Security tied more than 150 malicious Firefox extensions to a group it called GreedyBear. Koi claimed that group stole over $1 million in crypto.
Defense and Detection Guidance
Malicious Firefox extensions like these are hard to spot by name alone. Users and teams should:
- Install wallets only from links on the vendor’s official website.
- Check publisher names and spelling carefully before installing.
- Never type a recovery phrase into a new or unfamiliar extension.
- If you used any of these add-ons, create a new wallet on a clean device and move funds now.
- Defenders can hunt for the “Raabby WaIIet” string and add-ons that claim no data collection but call Cloudflare Workers.
Socket stresses one point. “Changing only the extension password does not revoke a stolen seed phrase or private key.”
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!