Mozilla has revoked the cryptographic signing key used for Firefox and Thunderbird downloads on Linux after an unencrypted copy of the key was accidentally committed to one of its private code repositories. The key is used to verify that downloaded tarballs are authentic and untampered. While there is no evidence of unauthorized access, Mozilla decided to revoke the key as a precautionary measure.
The revocation affects all files signed with the old key, meaning older downloads will no longer verify once users import the revocation. Most users need to take no action, but those who manually verify signatures must import the new key and the revocation certificate. Users installing Firefox from Mozilla’s RPM packages may encounter update failures and need to manually replace the key.
The replacement subkey was published on Monday with fingerprint 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3 and is valid until August 5, 2028. The revocation certificate uses reason code 2, indicating “key material has been compromised,” generated on August 6, 2026. This is the first revocation on the key, which had five earlier signing subkeys all retired by expiry.
Mozilla has not disclosed which repository held the key, how long it was exposed, or the safeguards added. The APT repository for Debian and Ubuntu users is unaffected, as it uses a different key. The disclosure follows a recent incident where attackers hijacked a GitHub account linked to the keyv npm package and deployed a worm targeting developer machines.
CVEs: CVE-2026-0001
Companies: Mozilla
Products: Firefox, Thunderbird
Original source: thehackernews.com