The malicious code embedded in these extensions transmitted stolen 64-character private keys directly to a Cloudflare Workers endpoint via URL query parameters. This discovery led to the immediate unpublishing of sixteen distinct browser extensions from the Mozilla Firefox ecosystem by early October. These malicious packages were meticulously crafted to impersonate well-known cryptocurrency wallet providers, specifically targeting users of Rabby Wallet and OKX Wallet. By mimicking the visual identity and user interface of these trusted tools, the attackers successfully tricked individuals into surrendering their most sensitive financial credentials. The operation demonstrated a high level of sophistication, utilizing legitimate infrastructure like Cloudflare to obfuscate data exfiltration. Unlike simple phishing sites that rely on external links, these extensions operated directly within the browser, providing a false sense of security while actively monitoring user input for recovery phrases.
1. The Strategy of Impersonation and Visual Deception
Researchers identified four specific extensions that were essentially repackaged versions of the authentic Rabby Wallet code, each containing over a thousand individual files. These malicious packages, such as “Raabby WaIIet”, utilized subtle misspellings to bypass brand detection while maintaining the overall look and feel of the original software. Interestingly, these clones often retained functional links to the official Rabby legal pages and support services, which further cemented the illusion of legitimacy for the unsuspecting user. By integrating the credential-stealing hooks directly into the background code and the wallet’s user interface, the malicious actors ensured they could capture recovery phrases and hexadecimal keys the moment a user attempted to import an existing wallet or create a new keyring. These hooks were designed to be non-intrusive, allowing the underlying wallet workflow to complete without error, so users would successfully set up their wallet and move assets into it.
In addition to the Rabby clones, the investigation uncovered twelve other extensions that leveraged an interface modeled after the popular OKX Wallet, often under the name “Portal WALLET”. These versions utilized branding elements and color schemes clearly intended to evoke the OKX user experience, providing a shared frontend that prompted users to input their 12- or 24-word recovery phrases. Once the data was entered, active background scripts processed the phrases and transmitted them to attacker-controlled servers, typically via standard HTTPS POST requests. Some variants included multiple fallback delivery methods, such as browser beacons and image requests, to ensure the stolen data reached its destination even if the primary connection was interrupted. Despite claims within the code comments that only metadata like word counts were being sent, forensic analysis confirmed that the full recovery phrases were being exfiltrated. This blatant contradiction underscores the limitations of automated store vetting.
2. Technical Exfiltration and Necessary Security Responses
The technical execution of this campaign highlighted a significant evolution in how browser-based malware operates, utilizing reputable services to receive stolen data. By employing Cloudflare Workers as an endpoint, the attackers made the traffic appear less suspicious to automated monitoring tools, while the use of URL query parameters allowed data to be logged in various server-side logs throughout the transit path. One interesting case involved “[email protected]”, which appeared to be technically flawed because the manifest file failed to correctly load the background script. Additionally, the frontend and background components utilized incompatible message types, effectively breaking the communication chain required for exfiltration. Despite these operational failures, the intent was undeniable, as the extension still contained the explicit code blocks for credential collection. This serves as a reminder that even buggy or broken software poses a massive threat if its purpose is malicious.
For individuals who interacted with these extensions, the path to remediation required swift action that went beyond simply deleting the software. If a user entered a recovery phrase into any of these clones, they recognized that the associated wallet was fully compromised and moved all assets to a new, secure address immediately. This incident proved that the threat landscape moved far beyond simple phishing into high-fidelity application impersonation, necessitating a shift toward hardware-based signing for sensitive tasks. Developers and browser manufacturers began exploring more rigorous vetting processes that included dynamic analysis of extension behavior rather than just manifest verification. Taking these proactive steps ensured that the decentralized nature of cryptocurrency remained a benefit rather than a vulnerability for the community. Ultimately, the removal of these extensions provided a temporary reprieve, but the responsibility for long-term security remained with users who practiced diligent verification of every financial tool.
