• News/
  • https://www.bleepingcomputer.com/news/security/ghostposter-attacks-hide-malicious-javascript-in-firefox-addon-logos/

GhostPoster attacks hide malicious JavaScript in Firefox addon logos

BleepingComputer
·
Bill Toulas
·
Published Dec 16, 2025
·
Updated

A new campaign dubbed 'GhostPoster' is hiding JavaScript code in the image logo of malicious Firefox extensions with more than 50,000 downloads, to monitor browser activity and plant a backdoor. The malicious code grants operators persistent high-privilege access to the browser, enabling them to hijack affiliate links, inject tracking code, and commit click and ad fraud. The hidden script is acting as a loader that fetches the main payload from a remote server. To make the process more difficult to detect, the payload is intentionally retrieved only once in ten attempts. Koi Security researchers discovered the GhostPoster campaign and identified 17 compromised Firefox extensions that either read the PNG logo to extract and execute the malware loader or download the main payload from the attacker's server. It should be noted that the malicious extensions are from popular categories: The researchers say that not all the extensions above use the same payload loading chain, but all of them exhibit the same behavior and communicate with the same infrastructure. The FreeVPN Forever extension was the one Koi Security analyzed initially after its AI tool flagged it for parsing the raw bytes of its logo image file to locate a JavaScript snippet hidden using the steganography technique. The JavaScript loader activates 48 hours later to fetch a payload from a hardcoded domain. A second backup domain is available if the payload is not retrieved from the first one. According to Koi Secur...

Read full article

Affected Software

2 affected components
Mozilla Firefox
Mozilla Firefox extensions
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a campaign called 'GhostPoster' that exploits Firefox addons by hiding malicious JavaScript in their logos.

2

What security implications are discussed in relation to the GhostPoster campaign?

The campaign allows attackers to monitor browser activity and install a backdoor on affected systems.

3

What products or software are specifically affected by the GhostPoster attacks?

The affected products include Mozilla Firefox and various Firefox extensions.

4

How many downloads do the malicious Firefox extensions reportedly have?

The malicious Firefox extensions involved in the GhostPoster campaign have more than 50,000 downloads.

5

What method do attackers use to conceal their malicious code in the GhostPoster attacks?

Attackers embed malicious JavaScript within the image logos of Firefox extensions to avoid detection.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203