Closed Bug 1543462 Opened 5 years ago Closed 5 years ago

Extension Block Request: avast-for-firefox

Categories

(Toolkit :: Blocklist Policy Requests, task)

task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: Spoji, Assigned: TheOne)

Details

Extension name avast-for-firefox, youtube-download-fast
Extension versions affected <all versions>
Platforms affected <all platforms>
Block severity hard

Reason

Malicious in nature (keylogger).

Extension IDs

{0913599d-3094-44a7-8cc2-b8467d5afc7c}
{7bee7f1b-d8ad-424d-807d-e69e6634988e}

Additional Information

The first Extension ID is an exact copy of the real add-on version 18.4.140 available at https://reviewers.addons.mozilla.org/en-US/reviewers/review/avast-online-security but with an added keylogger code inside the content_script common/scripts/z.js

The second one is another extension from the same dev.

I reviewed the add-ons and found that the first two exfiltrate user data without users' consent or control.

Sylvain, can you please file a new bug for the unrelated third add-on (and remove it from the list above)? Thank you!

The block for the first two add-ons has been staged. Philipp, can you please review and push?

Assignee: nobody → awagner
Status: NEW → ASSIGNED
Type: defect → task
Flags: needinfo?(sylvaing)
Flags: needinfo?(philipp)

Done

Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Flags: needinfo?(philipp)
Resolution: --- → FIXED

As requested, third extension ID has been moved to https://bugzilla.mozilla.org/show_bug.cgi?id=1543664

Flags: needinfo?(sylvaing)
You need to log in before you can comment on or make changes to this bug.