GhostPoster attacks hide malicious JavaScript in Firefox addon logos
ID: a304094d-2119-5869-add0-7dc77eea423f
STIX ID: report--a304094d-2119-5869-add0-7dc77eea423f
Feed Name: Bleeping Computer
A campaign named GhostPoster hides a JavaScript loader inside the PNG icons of popular Firefox extensions (17 identified) to fetch obfuscated payloads that create a persistent high-privilege browser backdoor. The loader uses steganography, delays activation (48 hours) and only retrieves payloads ~10% of the time to evade detection; payloads hijack affiliate links, inject tracking/analytics, strip security headers, bypass CAPTCHAs, and inject transient ad-fraud iframes. Researchers recommend removing the affected extensions and resetting critical passwords while Mozilla has removed the extensions and updated detection systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
