Security researchers have identified a coordinated cluster of 16 malicious Mozilla Firefox extensions designed to steal cryptocurrency wallet recovery phrases and private keys. The extensions disguise themselves as legitimate wallet portals, desktop utilities, and browser productivity tools — some impersonating well-known wallets such as Rabby and OKX — while their underlying code hooks into wallet import flows, captures seed phrases and private keys at the moment a user enters them, and exfiltrates those secrets to attacker-controlled infrastructure.
This is a supply-chain-adjacent threat that lands directly on the endpoint. Unlike phishing, which depends on a user visiting a fake site, these extensions operate inside the browser with the user's implicit trust. Anyone in your organization who manages cryptocurrency from a Firefox browser — treasury teams, finance staff, executives, developers holding testnet/mainnet keys — is a potential victim. A single compromised recovery phrase means total, irreversible loss of wallet funds, and increasingly, crypto theft is a funding and access vector for broader intrusion activity.
The urgency here is twofold: (1) seed phrase theft requires no further exploitation once the phrase is captured — the window for response is measured in minutes, and (2) browser extension stores remain a recurring blind spot in enterprise security programs. If you aren't inventorying browser extensions as part of endpoint telemetry, you are flying blind.
Technical Analysis
Affected Platform
- Browser: Mozilla Firefox (all supported versions — the abuse vector is the extension ecosystem itself, not a specific Firefox vulnerability)
- Extension source: Mozilla Add-ons store (addons.mozilla.org) and/or sideloaded extensions
- Impersonated brands: Rabby, OKX wallets, along with extensions posing as wallet portals, desktop utilities, and browser tools
- Target assets: BIP-39 recovery phrases (12/24-word seed phrases), raw private keys, and wallet credentials entered during wallet import/restore flows
No CVE is associated with this campaign — this is not a browser vulnerability. It is abuse of the extension trust model. There is no patch to apply; the fix is detection, removal, and user education.
Attack Chain
From a defender's perspective, the kill chain breaks down as follows:
- Distribution: The 16 extensions are published under names and branding that mimic legitimate crypto wallets and utilities. Threat actors rely on search results, sponsored listings, or direct links from phishing/social media to drive installs.
- Masquerading: Once installed, the extension presents a convincing wallet interface — import/restore screens that look identical to the real Rabby or OKX flows.
- Interception: Malicious JavaScript within the extension captures input during wallet import flows — specifically the recovery phrase fields and private key inputs. Because extensions run with privileged access to page content and their own background contexts, they can read form field values before any encryption or transmission to a legitimate service occurs.
- Exfiltration: Captured secrets are transmitted to attacker-controlled endpoints — typically HTTPS POST requests to domains unaffiliated with any legitimate wallet infrastructure.
- Monetization: The attacker sweeps the wallet. Blockchain transactions are irreversible; by the time the victim notices, funds are gone.
Why This Technique Works
- Seed phrases are the keys to the kingdom. Unlike passwords, they can't be rotated. Once exposed, the wallet must be abandoned entirely and funds moved to a new wallet generated on a clean device.
- Extension permissions are broad. Users grant permissions at install time without scrutiny, and even modest permissions (host access, storage) are sufficient for this attack since the malicious UI lives inside the extension itself.
- Firefox profiles persist across updates. Malicious extensions survive browser updates and can persist indefinitely if not explicitly removed.
Exploitation Status
This is an active, in-the-wild campaign — 16 distinct extensions were identified by researchers. At the time of writing, organizations should assume that variants beyond the named cluster exist, and that the same operators will re-upload under new publisher identities. Treat this as an ongoing threat class, not a one-time cleanup.
Detection & Response
The most reliable detection surface is the endpoint: Firefox profiles store extension data in predictable locations, and exfiltration generates observable network behavior. The detections below focus on three layers: (1) suspicious extension artifacts in Firefox profiles, (2) anomalous network egress from Firefox, and (3) clipboard/input behaviors associated with seed phrase theft.
Sigma Rules
---
title: Suspicious Extension Written to Firefox Profile
description: Detects creation of new extension files (XPI or unpacked extension directories) in Firefox profile extension folders outside of managed enterprise deployment. Cryptocurrency-stealing extensions impersonating wallets such as Rabby and OKX have been observed installing into user profiles.
author: Security Arsenal
date: 2026/10/20
references:
- https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html
- https://attack.mitre.org/techniques/T1176/
logsource:
category: file_event
product: windows
detection:
selection_path:
TargetFilename|contains:
- '\AppData\Roaming\Mozilla\Firefox\Profiles\'
selection_ext:
TargetFilename|contains:
- '\extensions\'
selection_type:
TargetFilename|endswith:
- '.xpi'
- '\manifest.json'
condition: selection_path and selection_ext and selection_type
falsepositives:
- Legitimate user-installed add-ons
- Enterprise-deployed extensions via policy (deployed under different paths)
level: medium
---
title: Firefox Network Connection to Rare or Newly-Observed Domain
description: Detects firefox.exe establishing HTTPS connections to domains associated with extension-based exfiltration. Tune the exclusion list to your environment's legitimate wallet and vendor infrastructure. Malicious wallet-impersonation extensions exfiltrate recovery phrases via HTTPS POST to attacker-controlled endpoints.
author: Security Arsenal
date: 2026/10/20
references:
- https://thehackernews.com/2026/10/16-malicious-firefox-extensions-pose-as.html
- https://attack.mitre.org/techniques/T1041/
logsource:
category: network_connection
product: windows
detection:
selection:
Image|endswith: '\firefox.exe'
DestinationPort: 443
filter_known:
DestinationHostname|contains:
- 'mozilla.com'
- 'mozilla.org'
- 'mozilla.net'
- 'firefox.com'
- 'mozaws.net'
- 'cloudfront.net'
- 'google.com'
- 'googleapis.com'
- 'gstatic.com'
- 'microsoft.com'
condition: selection and not filter_known
falsepositives:
- Normal browsing activity — this rule is intended as a hunting baseline; enrich with domain age/reputation scoring and alert only on low-reputation or newly-registered destinations
level: low
---
title: PowerShell or Script Process Enumerating Firefox Profile Data
description: Detects scripting processes accessing Firefox profile storage, which may indicate follow-on theft of stored credentials or extension data after seed phrase compromise, or automated reconnaissance of wallet-related browser data.
author: Security Arsenal
date: 2026/10/20
references:
- https://attack.mitre.org/techniques/T1555/
- https://attack.mitre.org/techniques/T1539/
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
- '\wscript.exe'
- '\cscript.exe'
CommandLine|contains:
- 'Mozilla\Firefox\Profiles'
- 'logins.json'
- 'key4.db'
- '\extensions\'
condition: selection
falsepositives:
- Legitimate browser forensics or backup tooling
- EDR inventory scripts
level: high
KQL Hunt (Microsoft Sentinel / Defender)
The following query hunts across Defender for Endpoint for new extension artifacts appearing in Firefox profiles within the hunt window, then joins against process network telemetry to flag hosts where Firefox communicated with low-prevalence destinations shortly after an extension appeared. Run it as a scheduled hunting query and tune prevalence thresholds for your environment.
let lookback = 14d;
let extensionEvents = DeviceFileEvents
| where TimeGenerated > ago(lookback)
| where FolderPath has @"\Mozilla\Firefox\Profiles\"
| where FolderPath has @"\extensions\"
| where FileName endswith ".xpi" or FileName =~ "manifest.json"
| summarize FirstSeen=min(TimeGenerated), ExtensionFiles=make_set(FolderPath, 20) by DeviceId, DeviceName;
extensionEvents
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where InitiatingProcessFileName =~ "firefox.exe"
| where RemotePort == 443
| summarize Destinations=make_set(RemoteUrl, 50), DestCount=dcount(RemoteUrl) by DeviceId
) on DeviceId
| project DeviceName, FirstSeen, ExtensionFiles, DestCount, Destinations
| order by FirstSeen desc
For environments ingesting Syslog/CEF from Linux endpoints running Firefox, pivot on Syslog and CommonSecurityLog for outbound connections to newly-registered or low-reputation domains sourced from browser processes, and correlate with extension directory artifacts collected via your EDR's file inventory.
Velociraptor VQL
This hunt artifact enumerates installed Firefox extensions across all user profiles on an endpoint and extracts the extension ID, name, and permissions from each manifest.json — giving you a fleet-wide extension inventory to compare against known-good lists and the indicators from this campaign.
-- Enumerate Firefox extensions across all user profiles and parse manifest metadata
SELECT FullPath AS ManifestPath,
parse_json(filename=FullPath).name AS ExtensionName,
parse_json(filename=FullPath).version AS Version,
parse_json(filename=FullPath).browser_specific_settings.gecko.id AS ExtensionID,
parse_json(filename=FullPath).permissions AS Permissions,
parse_json(filename=FullPath).host_permissions AS HostPermissions
FROM glob(globs='C:/Users/*/AppData/Roaming/Mozilla/Firefox/Profiles/*/extensions/*/manifest.json')
Follow up on hits by pulling network state for Firefox processes on affected hosts:
-- Snapshot active Firefox connections for triage on flagged hosts
SELECT Pid, Name, Pid AS ProcessId, Family, Type, Status,
Laddr, Raddr
FROM netstat()
WHERE Name =~ 'firefox'
AND Status =~ 'ESTABLISHED'
Remediation
Immediate Actions
- Inventory all Firefox extensions across the fleet. Use the VQL artifact or the script below to build a per-host extension list. Any extension not on an explicit allowlist should be treated as suspect.
- Remove identified malicious extensions. Cross-reference your inventory against the extension names/IDs published in the research covering this campaign. Remove any extension impersonating Rabby, OKX, or unknown "wallet portals."
- Treat exposed wallets as fully compromised. If a user entered a recovery phrase or private key into any browser-based wallet interface while a suspect extension was installed, assume the phrase is captured. Move funds to a new wallet generated on a clean, offline device — never reuse the compromised seed.
- Reset credentials and inspect browser storage. Malicious extensions with storage/host permissions may have had access to session tokens and other site data. Force password resets for accounts accessed in the affected browser profile and invalidate active sessions.
Removal and Hardening Script (PowerShell)
The following script enumerates Firefox extensions for all local user profiles, flags extensions that are not on a defined allowlist, and optionally removes flagged extension directories. Populate $AllowedExtensionIds with your approved enterprise extension IDs before running in enforcement mode.
# Firefox Extension Audit and Removal Script
# Run as Administrator. Test in audit mode (-Enforce:$false) before removing anything.
param(
[switch]$Enforce = $false
)
# Populate with your approved Firefox extension IDs (gecko IDs from manifest.json or XPI filenames)
$AllowedExtensionIds = @(
"uBlock0@raymondhill.net",
"jid1-example@jetpack" # replace with your approved IDs
)
$profilesRoot = "C:\Users"
$report = @()
Get-ChildItem -Path $profilesRoot -Directory -ErrorAction SilentlyContinue | ForEach-Object {
$user = $_.Name
$extRoot = Join-Path $_.FullName "AppData\Roaming\Mozilla\Firefox\Profiles"
if (Test-Path $extRoot) {
Get-ChildItem -Path $extRoot -Directory | ForEach-Object {
$extDir = Join-Path $_.FullName "extensions"
if (Test-Path $extDir) {
Get-ChildItem -Path $extDir -ErrorAction SilentlyContinue | ForEach-Object {
$extName = $_.Name
$isAllowed = $AllowedExtensionIds -contains ($extName -replace '\.xpi$','')
$report += [PSCustomObject]@{
User = $user
Profile = $_.Parent.Name
Extension = $extName
Path = $_.FullName
Allowed = $isAllowed
}
if (-not $isAllowed -and $Enforce) {
Write-Warning "Removing non-allowlisted extension: $extName (user: $user)"
Remove-Item -Path $_.FullName -Recurse -Force -ErrorAction SilentlyContinue
}
}
}
}
}
}
$report | Format-Table -AutoSize
$report | Export-Csv -Path ".\firefox-extension-audit.csv" -NoTypeInformation
Write-Host "Audit complete. Results written to firefox-extension-audit.csv"
Policy and Preventive Controls
- Enforce an extension allowlist via enterprise policy. Firefox supports the
ExtensionSettingspolicy (deployable via Group Policy orpolicies.json) to block all extensions except explicitly permitted IDs, and to force-install approved ones. This is the single most effective control against this threat class. - Disable sideloading. Ensure extensions can only be installed from the signed Mozilla Add-ons channel you control via policy — block installs from arbitrary XPI files.
- Segment crypto operations. Treasury or finance staff handling cryptocurrency should use dedicated, hardened machines (ideally hardware wallets for signing) — never general-purpose browsing workstations. A hardware wallet keeps the seed phrase off the browser entirely, neutralizing this entire attack class.
- Train users on the tell: legitimate wallets (Rabby, OKX, MetaMask) will never distribute through third-party "utility" extensions, and no legitimate flow asks for a seed phrase outside the official wallet software downloaded from a verified source.
- Add extension inventory to your IR playbooks. Browser extensions should be a standard collection item in any endpoint triage — they are a persistent, stealthy foothold that survives most cleanup routines.
User Guidance for Suspected Exposure
If any user suspects they entered a recovery phrase into a malicious extension:
- Disconnect the machine from the network but do not wipe it — preserve it for forensic review.
- From a separate, clean device, create a new wallet and transfer all funds immediately.
- Never reuse the compromised recovery phrase for any wallet, ever.
- Report the extension to Mozilla (via addons.mozilla.org abuse reporting) and file a report with relevant authorities (e.g., IC3 in the US) — wallet theft at scale is a prosecutable offense and reporting aids takedowns.
Conclusion
This campaign is a reminder that the browser extension layer is a fully operational attack surface — one that most EDR deployments barely observe. Sixteen extensions impersonating trusted wallet brands, intercepting seed phrases at the moment of entry, is a low-effort, high-yield operation that will be repeated. The defenders who fare best here are the ones who treat browser extensions like software inventory: enumerated, allowlisted, and monitored. If you can't answer "what extensions are installed on every Firefox instance in my fleet right now," that is your first gap to close — before the next cluster of lookalike wallets ships.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.