Firefox Joins Chrome and Edge as Malicious “Sleeper” Extensions Spy on Users

Over the past few years, browser extensions have quietly become one of the most overlooked security risks on the internet. They promise convenience — blocking ads, translating pages, managing downloads, or boosting productivity — but they also sit deep inside the browser, often with permission to read what we see and do online. Now, a new wave of research shows that Firefox has joined Chrome and Edge as a target of so-called “sleeper” extensions that spy on users, underscoring that no major browser is immune.

A problem that started elsewhere — and spread

The issue first gained widespread attention when security researchers uncovered dozens of malicious extensions in Google Chrome and Microsoft Edge. These extensions were not obviously malicious at first glance. In fact, many of them were genuinely useful when they first appeared in official extension stores. They offered features like PDF tools, search helpers, or shopping assistance and accumulated large user bases — in some cases, hundreds of thousands or even millions of installs.

Only later did the danger emerge. Through routine updates, attackers quietly injected spyware into these once-legitimate extensions. Because users rarely scrutinize extension updates, the malicious code spread silently, turning trusted add-ons into surveillance tools almost overnight.

Until recently, Mozilla Firefox was often viewed as a safer alternative, thanks to its privacy-focused reputation and more restrictive extension policies. That perception has now been challenged.

Firefox joins the list

Researchers have now confirmed that the same “sleeper extension” strategy has made its way into Firefox’s add-on ecosystem. The pattern is familiar: extensions that initially behaved as advertised were later updated to include hidden tracking functionality.

These malicious Firefox extensions were found to monitor browsing activity, collect visited URLs, and in some cases establish communication channels with remote servers controlled by attackers. From there, the extensions could receive further instructions, making them far more dangerous than simple trackers.

While Mozilla has removed the identified extensions, the discovery itself is troubling. It shows that even browsers with strong privacy branding and vetting processes can be exploited by patient attackers willing to play the long game.

What exactly is a “sleeper” extension?

The term “sleeper extension” refers to a malicious add-on that stays dormant — or behaves legitimately — for a period of time. This dormancy allows it to pass security reviews and build trust with users. Once it has gained enough installations, the attacker activates its true purpose through an update or a remote trigger.

This tactic is especially effective because extension stores largely focus on the initial version of an add-on. Updates are harder to police at scale, and small changes in code can hide major functionality shifts. By the time suspicious behavior is detected, the extension may already be deeply embedded in thousands of browsers.

In some cases, researchers found that malicious code was deliberately obfuscated or hidden in unexpected places, such as image files or unused scripts, making detection even harder.

Why extensions are such a powerful attack vector

Browser extensions enjoy a level of access that most websites can only dream of. Depending on their permissions, they may be able to:

  • Read and modify web pages you visit
  • Track every site you open and every search you make
  • Access cookies and session data
  • Inject scripts into pages in real time

For a malicious actor, this is gold. Unlike traditional malware, extensions don’t need to break out of the browser sandbox — they already live inside it.

This makes extension-based spyware particularly dangerous for activities like online banking, work logins, and private communications. Even if passwords are not directly stolen, session hijacking or behavioral profiling can expose users to fraud, identity theft, or targeted attacks.

Not just careless users

One of the most uncomfortable truths about this situation is that it does not only affect reckless users who install random add-ons. Many of the compromised extensions looked professional, had positive reviews, and were hosted in official browser stores.

In some cases, the original developer may not even have been malicious. Security experts have noted that attackers sometimes buy popular extensions from their creators or compromise developer accounts, then push malicious updates under a trusted name. From the user’s perspective, nothing appears to change — except behind the scenes.

How browser makers are responding

Browser vendors are taking the issue seriously, but they face an uphill battle. Chrome, Edge, and Firefox have all removed identified malicious extensions and tightened certain review processes. Automated scanning, behavioral analysis, and permission audits are improving, but attackers adapt just as quickly.

The core challenge is scale. With millions of extensions and constant updates, it is nearly impossible to manually review every change. This means some malicious updates will inevitably slip through, even in well-run ecosystems.

Mozilla, in particular, has emphasized that its response mechanisms allowed it to remove the affected Firefox add-ons quickly once they were identified. Still, the fact that they made it in at all shows the limits of prevention.

What users can realistically do

While the idea of spyware hiding in extensions is unsettling, users are not powerless. A few practical habits can significantly reduce risk:

First, audit your extensions regularly. If you haven’t used an extension in months, remove it. Fewer extensions mean fewer attack surfaces.

Second, be suspicious of permissions. An extension that asks for access to “all websites” or “all browsing data” should have a very clear reason for doing so. If that reason isn’t obvious, it’s a red flag.

Third, stick to well-maintained extensions from known developers, but don’t rely on reputation alone. Even popular add-ons can change hands or behavior over time.

Finally, keep your browser and security software up to date. While they won’t catch everything, they add layers of defense that make silent spying harder.

The spread of sleeper extensions across Chrome, Edge, and now Firefox highlights a larger reality: convenience and security are often in tension. Extensions make the web easier to use, but they also require trust — trust that can be abused.

This is not a sign that one browser is “worse” than another. Instead, it shows that the extension model itself is inherently risky and needs constant vigilance from both browser makers and users.

As attackers continue to refine their tactics, the safest mindset may be a simple one: every extension is a potential doorway into your digital life. Open only the doors you truly need — and keep checking who might be standing behind them.