Build1 distinct publisher3 min readUpdated
Browser extensions update themselves silently unless new permissions are requested. Socket says it is now watching every version of every add-on in Mozilla's directory.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Socket has extended its browser extension coverage to Firefox, scanning every add-on listed in Mozilla's official addons.mozilla.org directory, which the company says Mozilla's public API put at 97,100 Firefox-compatible extensions at the time of publication [1][2]. The company, which describes the Firefox coverage as experimental, says it will keep analysing new releases rather than scanning once, which is the part that matters: Firefox delivers add-on updates from the official directory automatically, and only prompts the user again when an update requests permissions it does not already hold [1][3][10].
That is the gap most endpoint tooling ignores. A managed-browser inventory can usually produce a list of extension IDs, but Socket's argument is that a name, a publisher, an install count and a permission list say nothing about what the code does, where it sends data, or whether the behaviour changed in the current version [8]. An extension can read and modify pages, access tabs, touch the clipboard, observe browsing activity and talk to external services [7]. Mozilla applies automated validation and signing to extensions for release and beta Firefox, with manual review possible at submission or later [9]. None of that constitutes a per-version review gate.
The research Socket published alongside the launch is the load-bearing part. Socket says it identified 77 linked Firefox extension identities active from at least March through August 2026, confirmed 40 of them as malicious, and classified the remaining 37 as deceptive sports-score shells tied to the same code, infrastructure and version histories [11][12][13]. That is roughly 52 percent of the cluster confirmed malicious, over a window of at least six months [1][2]. According to Socket, the malicious set served remotely controlled wallet-phishing pages, captured recovery phrases and private keys, exfiltrated wallet keyrings, and stole credentials and clipboard contents [14].
The permission telemetry would not have flagged most of it. One remote-loader cluster requested only `storage` and `tabs`, which Socket offers as evidence that a benign-looking manifest is not a clean bill of health [15]. And the version histories show the repurposing pattern directly: nine of the confirmed malicious identities had previously shipped as sports-score shells before becoming wallet stealers, and others moved from utility names including Visited Link Marker and Flow Pomodoros to Rabby-style wallets carrying credential and clipboard-stealing code [16][17]. Nine of 40 is close to a quarter of the confirmed malicious identities arriving through an identity that users had already accepted [3].
Scale explains why this is an enterprise problem rather than a consumer one. Mozilla says nearly half of Firefox users have installed at least one extension, with more than 10,000 developers contributing [6]. The ecosystem has been a headline feature since Firefox 1.0 launched in November 2004 with more than 100 extensions, and standardised on the WebExtensions model with Firefox 57 in 2017 [4][5].
What to watch: whether "experimental" coverage produces version-level diffs operators can act on, or only a risk score attached to an extension ID. The useful output is a diff between the version installed and the version now shipping, since Socket's own case files turn on exactly that transition [16][17]. Also worth checking is how much of the 97,100 gets meaningful analysis rather than enumeration, and whether detections arrive before Firefox's automatic update mechanism has already delivered the new code [2][10].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Socket is expanding its browser extension security coverage to Firefox, described as experimental protection, giving security teams visibility into extensions used across their organizations and helping identify malicious behavior, excessive permissions, data collection, suspicious infrastructure, and risky changes between versions.
Socket now proactively scans every Firefox extension listed in Mozilla's official addons.mozilla.org directory; at the time of publication Mozilla's public API lists 97,100 Firefox-compatible extensions.
Socket says it analyses those extensions and continues monitoring new releases so security teams can see when an extension's behavior changes.
When Firefox 1.0 launched in November 2004, Mozilla highlighted more than 100 available extensions as a defining feature.
The Firefox extension ecosystem moved to the WebExtensions model with Firefox 57 in 2017, creating a more standardized framework shared with other browsers.
Mozilla says nearly half of Firefox users have installed at least one extension, with more than 10,000 developers contributing to the ecosystem.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific but single-source and vendor-authored
Every claim rests on one publisher: Socket's own blog. The campaign findings are unusually concrete for a vendor post - counts (77 linked identities, 40 malicious, 37 shells, nine repurposed), a dated activity window, named extensions, and a named low-permission loader cluster - and the platform mechanics (signing, automatic updates, prompt-only-on-new-permissions) are checkable against Mozilla's documented behavior. But there is no independent corroboration, no indicators of compromise or extension IDs, no install counts, and no efficacy measurement for the scanning capability itself, so the evidence base is credible-but-unverified rather than strong.
Announced and experimental; no uptake evidence
The only adoption signal is the launch itself, explicitly described as experimental protection, plus a scanning-coverage figure (97,100 directory extensions) that measures the vendor's own crawl rather than customer use. There are no customers, deployments, seats, or usage figures for the Firefox capability, and the availability line is truncated in the source. Mozilla's ecosystem statistics describe the extension market, not adoption of this control.
Modestly overstated framing over unverified efficacy
The headline framing - protecting the Firefox extension ecosystem, watching every version of every add-on - runs ahead of what is shown: an experimental capability with no detection efficacy, latency, or false-positive data, and no evidence that the 40 malicious identities were removed or that any customer benefited. The gap is limited rather than large because the threat research is specific and dated, the 'experimental' caveat is stated up front, and the underlying mechanism claim (silent updates within granted permissions) is independently plausible.
Vendor research motivating its own launch
Socket is the researcher, the product owner and the publisher. The post's structure moves from threat findings straight to the capability list and an enterprise availability note, so the research directly underwrites demand for the announced feature. No competing or countervailing publisher appears in the cluster, and no disclosure or third-party review of the findings is offered.
Moderate: specific claims, one interested source
Confidence is limited by single-publisher sourcing and a strong commercial incentive, and lifted by the specificity and datedness of the underlying claims plus mechanism claims that align with known browser update behavior. Enough to act on the risk framing and pilot the control; not enough to treat the coverage or efficacy assertions as verified.
build
77 linked Firefox add-ons, one pipeline: store review is a checkpoint, not a control1 distinct publisher
build
The npm audit that works because it never installs the package1 distinct publisher
invest
Mozilla's pitch against Gemini-wired Chrome is an off switch and a search deal with Exa2 distinct publishers
build
AWS gives software supply chain its own Security Hub category, with two vendors in it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026