A malicious campaign known as GhostPoster has been discovered leveraging the logo files of 17 Mozilla Firefox browser add-ons to conceal JavaScript code that enables a range of fraudulent activities. These extensions, which were collectively downloaded over 50,000 times, posed as legitimate tools such as VPNs, ad blockers, screenshot utilities, and translation services. Security researchers from Koi Security found that the malicious code was hidden within the image files using steganography, allowing it to evade detection. Once activated, the code would hijack affiliate links, inject tracking scripts, and facilitate click and ad fraud, while also stripping away browser security protections and opening a backdoor for remote code execution.
The attack chain is initiated when the extension loads and fetches its logo file, which is parsed for a specific marker to extract the embedded JavaScript loader. This loader then attempts to retrieve the main malware payload from attacker-controlled domains, but only does so 10% of the time and with a 48-hour delay between attempts, making detection more difficult. The extensions have since been removed from the Firefox add-on store, but the campaign highlights the risks of malicious browser extensions and the sophisticated evasion techniques employed by threat actors. All identified extensions communicated with the same malicious infrastructure, and not all used identical payload delivery methods, but they shared the same core behaviors and objectives.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, the malicious extensions were removed from Firefox in at least some cases, though reporting indicated that many were still available on the Firefox Add-Ons page at the time of publication. Users were advised to uninstall affected add-ons and reset important account passwords.
Koi Security reported that 17 Firefox extensions were involved in the GhostPoster operation and published technical details on the malware's steganographic delivery and evasion methods. The researchers assessed the infrastructure and behavior as likely tied to a single threat actor or group.
The compromised Firefox add-ons were downloaded over 50,000 times, exposing a large number of users to affiliate link hijacking, ad and click fraud, and browser monitoring. The campaign used delayed and probabilistic payload delivery to reduce the chance of detection.
A threat actor deployed the GhostPoster campaign through 17 malicious Firefox extensions disguised as VPNs, ad blockers, and translation tools. The add-ons used steganography to hide JavaScript in logo images and established persistent, high-privilege browser access for fraud, tracking, and potential remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.