"The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to attacker-controlled Cloudflare Workers," Socket researcher Joseph Edwards said in an analysis.
How the malicious extensions operate
Security researchers identified 16 Mozilla Firefox add-ons whose embedded code waits for wallet import flows, captures mnemonic recovery phrases and private keys, and then attempts to exfiltrate those secrets to an attacker-controlled Cloudflare Workers endpoint. The campaign uses fake wallet interfaces and credential-handling logic that mirror legitimate wallet software to trick users into pasting sensitive secrets into the impostor UI.
The 16 extensions and the wallets they impersonate
Socket's analysis lists the add-ons by their extension identifiers and package names. Four are clones of Rabby Wallet and the remainder are targeted clones of OKX Wallet. The extensions named in the report are:
- view-focus-bright@webtools.co@6.12.2
- quick-track-nest@tabtools.co@8.1.18
- vibe-kit-tool@fasttools.co@9.21.9
- edge-hub-snap@protools.net@4.12.24
- core-hub-peak@neattools.example@8.24.21
- sipoo-grozza@browserweb.com@2.1
- mozart-seo@webtools.com@1.4
- clean-file-bar@neattools.com@4.21.8
- clean-net-timer@plugify.example@4.17.1
- manager-square@webtools.com@1.4
- manager-course@webtools.com@1.4
- val-andrew@browserweb.com@1.4
- manager-team@browserweb.com@1.4
- valory-andrew@browserweb.com@1.4
- franklin-uk@browserweb.com@1.4
- franklin-uro@browserweb.com@1.4
According to the analysis, all but one of the identified add-ons contact the same Cloudflare Workers domain pattern: "*.icy-star-f45c.workers[.]dev". The stated end goal of the campaign is to collect mnemonic phrases and private keys and exfiltrate them to that domain.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildInfrastructure and actor behavior: reuse with superficial rotation
Socket characterizes the activity as a continuation of an earlier wave documented in August 2026. The findings indicate a pattern: threat actors rotate visible package metadata — names, versions, extension IDs, descriptions and presentation — while reusing the same wallet interfaces, credential-handling logic and network infrastructure. That reuse is what allowed researchers to link the new cluster to prior activity.
All the identified extensions had been removed by October 5, 2026, the report notes. But the analysis implies the attackers rely on frequent republishing and small, iterative changes to evade detection while keeping the core exfiltration plumbing intact.
Related malicious-extension campaigns discovered recently
The Firefox wallet-clone cluster was reported alongside several other extension-based threats observed in recent months. Socket's write-up places this instance in a broader context of extension abuse and includes these identified campaigns and malicious add-ons:
- A Firefox extension called "ID- Pay" (pdf-para-texto@extensao.local) that poses as a utility for identity verification before opening protected PDF documents but harbors functionality to fetch a remote payload from attacker-controlled infrastructure and inject JavaScript into the legitimate "accounts.google[.]com" domain to steal session cookies.
- A cluster of 32 malicious browser extensions across the Chrome Web Store and Microsoft Edge Add-ons Store that masquerade as benign productivity utilities, but harvest data, monitor user browsing habits, and stealthily replace the active tab with a destination URL specified in a remotely-retrieved configuration; that campaign has been active since March 2025 and was attributed to a Korean-speaking threat actor.
- About 30 malicious browser extensions published under the names of legitimate, high-profile financial personalities designed to redirect victims to cryptocurrency wallet phishing pages to steal recovery phrases, while skipping English-speaking users and analysis environments.
- A cluster of 31 Russian-language Chrome extensions advertised as VPNs for specific blocked services, which route browser traffic through a proxy whose server list is fetched from a GitHub Pages URL (with Blogger, Google Docs, and Telegram used for redundancy) after installation.
- A Chrome Web Store extension named Stylish that intercepts every ChatGPT, Gemini, Claude, Perplexity, Character.AI, and GitHub Copilot conversation and forwards the full response text to its operator.
- A Chrome Web Store extension named "Urban VPN" that includes an "anti-phishing" feature that never returns a phishing warning and silently transmits visited URLs to servers operated by BIScience; its developers later said AI-related processing occurs only after an "AI Protection" feature is enabled, and addressed a high-severity vulnerability earlier this May.
- "Pop up blocker for Chrome™ - Poper Blocker," marketed as an ad blocker, but shipping an interpreter that downloads and interprets instructions from a command-and-control server to collect browser fingerprints, browsing history, social media profile information and AI chatbot interactions — behavior used to circumvent Google's Manifest V3 rules.
What this means for technologists, end users, and organizations
- Technologists and security teams: audit browser extensions within managed environments, adopt runtime monitoring approaches, and deploy behavior-based extension monitoring technologies to detect suspicious activity, as recommended in the report.
- End users and wallet holders: users who installed any of the listed extensions and entered a real recovery phrase or private key into the fake wallet interfaces should assume compromise, create a new wallet from a clean system, and move their assets.
- Enterprises and procurement teams: review installed browser extensions in corporate environments and remove those that are unnecessary; the report underscores the need for inventories and tighter controls over what extensions are permitted.
The immediate technical takeaway is plain: the superficial details of an extension can be changed quickly, but the underlying credential-extraction code and the Cloudflare Workers destination persisted across iterations. Although the identified add-ons were removed by October 5, 2026, the documented pattern — rotate metadata, reuse core logic and infrastructure — is a clear signal to defenders: forensic indicators tied to behavior and destination infrastructure will be more durable than any single package name. Monitor for reappearance of similar wallet interfaces and Cloudflare Workers domains, and treat any real mnemonic or private-key pastes into unexpected browser-based wallets as a likely compromise.




