Monday , August 24 2026
17 Firefox Extensions

17 Firefox Extensions Hide Malware in Icon Files, Compromising Thousands of Users

At least 17 Firefox extensions managed to evade detection by hiding malware in their icons. Thousands of users have been compromised, and these harmful add-ons remain accessible on the Firefox platform. Koi Security found 17 Firefox extensions that look safe, with no visible malicious scripts. They offer services like “free VPNs”, screenshots, live transitions, weather.”

Source: Koidex report for Free VPN

Koi researchers found that certain extensions focused on icons, examining raw bytes, which held hidden malware loaders.

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

“We found a hidden extraction routine. The extension wasn’t just displaying the logo. It was searching through the image data, looking for a marker that shouldn’t be there,” said the researchers.

Attackers modified the PNG icon files by adding malicious code after the image data, marked by three equal signs (“===”). While the icon looks normal to users, this method helps bypass security scans. This technique is called steganography.

The campaign includes at least 17 extensions and has over 50,000 downloads so far. The extension Free VPN Forever has the highest installations, totaling 16,000.

The malicious add-on initiates a multi-stage infection. The icon serves only as a loader for the real malware, which extracts hidden code once the extension is activated. To avoid detection, it behaves inconsistently, waiting 48 hours between server check-ins and infecting only 10% of users.

“What they actually deliver is a multi-stage malware payload that monitors everything you browse, strips away your browser’s security protections, and opens a backdoor for remote code execution,” the Koi researchers said.

The malware redirected affiliate links, stealing commissions from purchases on sites like Taobao and JD.com. It also used hidden iframes to load content from attacker servers for ad and click fraud.

“Free VPNs promise privacy, but nothing in life comes free. Again and again, they deliver surveillance instead,” the researchers warn.

Koi warns users about dangerous extensions, as most of them are still live on the Firefox Add-ons marketplace:

free-vpn-forever
screenshot-saved-easy
weather-best-forecast
crxmouse-gesture
cache-fast-site-loader
freemp3downloader
google-translate-right-clicks
google-traductor-esp
world-wide-vpn
dark-reader-for-ff
translator-gbbd
i-like-weather
google-translate-pro-extension
谷歌-翻译
libretv-watch-free-videos
ad-stop
right-click-google-translate

Check Also

cable

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside …