Closed Bug 1518580 Opened 6 years ago Closed 6 years ago

Extension block request: Iamme {43ecded1-f7cb-4bb6-a03d-4bec23b9f22d}

Categories

(Toolkit :: Blocklist Policy Requests, task)

task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: philipp, Assigned: TheOne)

Details

(Whiteboard: [extension])

Extension name: Iamme
Extension UUID: {43ecded1-f7cb-4bb6-a03d-4bec23b9f22d}
Extension versions to block: 5.3.1 (unsure about the rest)
Applications, versions, and platforms affected: all
Block severity: hard

Reasons: i have come across malvertising that is redirecting users to a trap page that's prohibiting users from closing the tab and "offering" the referenced addon for installation - so i'm assuming the extension is containing malicious code.

the extension shares the same description as this amo listed extension which is also reported to contain obfuscated code that is getting injected into websites according to recent reviews there, so perhaps they should be investigated together: https://addons.mozilla.org/firefox/addon/reopen-closed-tab/

both appear to be a rip off from the genuine https://addons.mozilla.org/firefox/addon/undoclosetabbutton/

Group: toolkit-core-security

Philipp, thank you for this report!

(In reply to [:philipp] from comment #0)

the extension shares the same description as this amo listed extension which is also reported to contain obfuscated code that is getting injected into websites according to recent reviews there, so perhaps they should be investigated together: https://addons.mozilla.org/firefox/addon/reopen-closed-tab/

We decided it's best to separate the two, would you mind filing another blocklist request for this one please?

Assignee: nobody → awagner
Status: NEW → ASSIGNED

The block for {43ecded1-f7cb-4bb6-a03d-4bec23b9f22d} has been staged. Fallen, could you please review and push?

Flags: needinfo?(philipp)

Done

Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Flags: needinfo?(philipp)
Resolution: --- → FIXED
Type: enhancement → task
You need to log in before you can comment on or make changes to this bug.