logo

GhostPoster attacks hide malicious JavaScript in Firefox addon logos

ID: a304094d-2119-5869-add0-7dc77eea423f

STIX ID: report--a304094d-2119-5869-add0-7dc77eea423f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A campaign named GhostPoster hides a JavaScript loader inside the PNG icons of popular Firefox extensions (17 identified) to fetch obfuscated payloads that create a persistent high-privilege browser backdoor. The loader uses steganography, delays activation (48 hours) and only retrieves payloads ~10% of the time to evade detection; payloads hijack affiliate links, inject tracking/analytics, strip security headers, bypass CAPTCHAs, and inject transient ad-fraud iframes. Researchers recommend removing the affected extensions and resetting critical passwords while Mozilla has removed the extensions and updated detection systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.