Skip to content

Build1 publisher3 min readPublished

Socket turns on continuous scanning for all 97,100 Firefox add-ons

Browser extensions update themselves silently unless new permissions are requested. Socket says it is now watching every version of every add-on in Mozilla's directory.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Socket is expanding its browser extension security coverage to Firefox, described as experimental protection, giving security teams visibility into extensions used across their organizations and helping identify malicious behavior, excessive permissions, data collection, suspicious infrastructure, and risky changes between versions.
  • Socket now proactively scans every Firefox extension listed in Mozilla's official addons.mozilla.org directory; at the time of publication Mozilla's public API lists 97,100 Firefox-compatible extensions.
  • Socket says it analyses those extensions and continues monitoring new releases so security teams can see when an extension's behavior changes.
  • When Firefox 1.0 launched in November 2004, Mozilla highlighted more than 100 available extensions as a defining feature.
  • The Firefox extension ecosystem moved to the WebExtensions model with Firefox 57 in 2017, creating a more standardized framework shared with other browsers.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

Socket has extended its browser extension coverage to Firefox, scanning every add-on listed in Mozilla's official addons.mozilla.org directory, which the company says Mozilla's public API put at 97,100 Firefox-compatible extensions at the time of publication [1][2]. The company, which describes the Firefox coverage as experimental, says it will keep analysing new releases rather than scanning once, which is the part that matters: Firefox delivers add-on updates from the official directory automatically, and only prompts the user again when an update requests permissions it does not already hold [1][3][10].

That is the gap most endpoint tooling ignores. A managed-browser inventory can usually produce a list of extension IDs, but Socket's argument is that a name, a publisher, an install count and a permission list say nothing about what the code does, where it sends data, or whether the behaviour changed in the current version [8]. An extension can read and modify pages, access tabs, touch the clipboard, observe browsing activity and talk to external services [7]. Mozilla applies automated validation and signing to extensions for release and beta Firefox, with manual review possible at submission or later [9]. None of that constitutes a per-version review gate.

The research Socket published alongside the launch is the load-bearing part. Socket says it identified 77 linked Firefox extension identities active from at least March through August 2026, confirmed 40 of them as malicious, and classified the remaining 37 as deceptive sports-score shells tied to the same code, infrastructure and version histories [11][12][13]. That is roughly 52 percent of the cluster confirmed malicious, over a window of at least six months [1][2]. According to Socket, the malicious set served remotely controlled wallet-phishing pages, captured recovery phrases and private keys, exfiltrated wallet keyrings, and stole credentials and clipboard contents [14].

The permission telemetry would not have flagged most of it. One remote-loader cluster requested only `storage` and `tabs`, which Socket offers as evidence that a benign-looking manifest is not a clean bill of health [15]. And the version histories show the repurposing pattern directly: nine of the confirmed malicious identities had previously shipped as sports-score shells before becoming wallet stealers, and others moved from utility names including Visited Link Marker and Flow Pomodoros to Rabby-style wallets carrying credential and clipboard-stealing code [16][17]. Nine of 40 is close to a quarter of the confirmed malicious identities arriving through an identity that users had already accepted [3].

Scale explains why this is an enterprise problem rather than a consumer one. Mozilla says nearly half of Firefox users have installed at least one extension, with more than 10,000 developers contributing [6]. The ecosystem has been a headline feature since Firefox 1.0 launched in November 2004 with more than 100 extensions, and standardised on the WebExtensions model with Firefox 57 in 2017 [4][5].

What to watch: whether "experimental" coverage produces version-level diffs operators can act on, or only a risk score attached to an extension ID. The useful output is a diff between the version installed and the version now shipping, since Socket's own case files turn on exactly that transition [16][17]. Also worth checking is how much of the 97,100 gets meaningful analysis rather than enumeration, and whether detections arrive before Firefox's automatic update mechanism has already delivered the new code [2][10].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories