Security researchers from the Socket Threat Research Team have uncovered a sophisticated network of eight malicious Firefox browser extensions that actively steal OAuth tokens, passwords, and spy on users through deceptive tactics. The investigation initially began with a single malicious extension called “Shell Shockers” but quickly expanded to reveal an entire network of fake gaming extensions operated by threat actor mre1903. Security experts recommend that users regularly audit installed browser extensions, removing any that request permissions exceeding their stated functionality. Users should immediately review their installed Firefox extensions and remove any that match the identified malicious applications to protect their personal data and authentication credentials. The combination of social engineering tactics with technical sophistication makes these extensions particularly effective against unsuspecting users who trust familiar game names and utility promises. The discovery reveals a coordinated campaign that exploits popular gaming titles and utility applications to compromise user security across the Firefox ecosystem. Browser extensions have become increasingly favored attack vectors due to their trusted status, extensive permissions, and ability to execute within browsers’ security contexts. The malicious code specifically targets Google Calendar APIs, requesting read-only permissions that allow attackers persistent visibility into users’ meeting schedules, travel plans, business activities, and contact information. This extension implements advanced OAuth credential theft operations, stealing Google Authentication tokens that provide ongoing access to sensitive personal and business data. This cybercriminal, active since June 2018, has systematically created fraudulent extensions that masquerade as popular games, including Little Alchemy 2, 1v1.LOL, Krunker io Game, Five Nights at Freddy’s, and Bubble Spinner.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 07 Jul 2025 09:45:12 +0000