Top Firefox extensions can hide silent malware using easy pre-fab tool
The most popular Firefox extensions with millions of active users are open to attacks that can quietly compromise machines and pass Mozilla's automated and human security tests.
The extension reuse attacks exploit weaknesses in the structure of Firefox extensions such that malicious activity can be hidden behind legitimate functionality.
For example, attackers could duplicate a popular but vulnerable extension to reuse attacks and write their own machine-pwning functionalities. The researchers explained that extensions run with elevated privileges and access to information, so a malicious extension could steal private browsing data, passwords, and sensitive system resources.