Malware found in Firefox Add-ons

by certifiedbug on February 5, 2010

in Browser

Security Issue on AMO according to Mozilla alert.

Two experimental add-ons, Version 4.0 of Sothink Web Video Downloader and all versions of Master Filer were found to contain Trojan code aimed at Windows users. Version 4.0 of Sothink Web Video Downloader contained Win32.LdPinch.gen, and Master Filer contained Win32.Bifrose.32.Bifrose Trojan. Both add-ons have been disabled on AMO.

Impact to users

If a user installs one of these infected add-ons, the trojan would be executed when Firefox starts and the host computer would be infected by the trojan. Uninstalling these add-ons does not remove the trojan from a user’s system. Users with either of these add-ons should uninstall them immediately. Since uninstalling these extensions does not remove the trojan from a user’s system, an antivirus program should be used to scan and remove any infections.

Mozilla

In May of 2008 Mozilla admitted that a worm inside a Vietnamese language add-on had gone undetected for months.

Certifiedbug November 23, 2009: Vulnerabilities in Firefox extensions

Edit
Update on AMO Security Issue

Leave a Comment

Previous post: Microsoft Security Advisory (980088)

Next post: Microsoft Security Bulletin Release February 2010