Home / Companies / Socket / Blog / Post Details
Content Deep Dive

8 More Malicious Firefox Extensions: Exploiting Popular Game Recognition, Hijacking User Sessions, and Stealing OAuth Credentials

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
1,112
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

Eight new malicious Firefox extensions have been identified, exploiting popular game recognition to hijack user sessions and steal OAuth credentials, posing a significant threat across all major browsers. These extensions masquerade as well-known games like Little Alchemy 2 to exploit user trust, redirecting them to scam sites instead of providing actual gaming functionality. Among them, GimmeGimme secretly hijacks shopping sessions on major European e-commerce sites for affiliate profits, while VPN Grab A Proxy Free tracks users through invisible iframes and proxies, compromising privacy and security. CalSyncMaster, posing as a Google Calendar tool, steals OAuth tokens, allowing persistent access to sensitive data, highlighting the evolution of browser extension threats from simple scams to sophisticated data theft. This underscores the need for regular auditing of browser extensions, careful permission reviews, and the use of automated detection tools to maintain security in this rapidly evolving threat landscape.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.