Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
browser-xpi-malware-scanner — A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics, steganography, base64 payloads, zip-tricks, remote-code execution, polyglot tricks, meta data tricks in an attempt to give the analysist information about where deeper analysis is needed. | Kitploit
Tools/GitHubGitHub/ernos/browser-xpi-malware-scanner
Static AnalysisVulnerability AnalysisCode AnalysisForensicsSteganographyMalware AnalysisPapers & ResearchLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
ernos/browser-xpi-malware-scanner

browser-xpi-malware-scanner

View Repository
8375 months agoNot yet reviewed

About

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics, steganography, base64 payloads, zip-tricks, remote-code execution, polyglot tricks, meta data tricks in an attempt to give the analysist information about where deeper analysis is needed.

Share

XPI Analyzer — Firefox Extension Security Scanner

A command-line tool that analyzes Firefox extension files (.xpi) for signs of malware, obfuscation, hidden payloads, steganography, and other techniques used to sneak malicious code past extension review teams.

What It Does

extension-scanner.py tears open a Firefox extension and performs a battery of security checks across every file inside it. It then produces a color-coded report with findings ranked by severity.

Guides/Tutorials on how to use this scanner to find malware live on Firefox/Mozilla's extension store and further examining them

  • Malware Analysis: Using browser-xpi-malware-scanner.py to find malware in the wild
  • The Ad-Blocker That Steals Your Clicks: Inside "Supreme Adblocker for Youtube"
  • How I Built a Browser Extension Malware Scanner — And Used It to Expose a Malicious "YouTube Downloader"

Checks Performed

CategoryWhat It Looks For
PermissionsDangerous or overly broad permissions (nativeMessaging, <all_urls>, debugger, desktopCapture, etc.)
Content Security Policyunsafe-inline, unsafe-eval, remote script sources in CSP
JavaScript Obfuscationeval(), atob(), Function() constructor abuse, hex escape sequences, split/join/reverse reassembly, encoded string literals, setTimeout with string arguments
Suspicious URLsHardcoded external domains classified as known-bad (blocklist hit → HIGH), unknown (not on allowlist → MEDIUM), or known-good (allowlisted → suppressed). Run --update-blocklist to refresh the domain blocklist from URLhaus and Peter Lowe's list.
Credentials & SecretsHardcoded API keys, tokens (AWS, GitHub, Slack, Google), passwords, private keys, and IP addresses
Base64 PayloadsDecodes embedded base64 blobs and scans them for executables, scripts, and network code
PNG SteganographyDetects data appended after PNG IEND and automatically decodes the trailer (base64, zlib, gzip, and combinations); decoded payloads are recursively scanned for JS obfuscation, credentials, and suspicious URLs. Also detects unknown chunk types, LSB channel anomalies, and unusually high pixel entropy
File MetadataMagic-byte detection of executables (.exe, .elf, .dylib), double extensions (e.g. photo.png.js), suspicious filenames (keylog, miner, wallet)
Polyglot FilesFiles that are simultaneously valid in two formats (e.g. HTML + ZIP)
ZIP TricksPath traversal entries, null bytes in filenames, duplicate entries that could fool parsers, payload-carrying ZIP comments
Remote CodeBackground pages or service workers loaded from remote URLs
High EntropyFiles or string literals with suspiciously high entropy (likely encrypted or compressed payloads)
API AbuseBrowser extension API calls that indicate data theft or exfiltration: cookies.getAll({}), tabs.query({}), history.search, keyboard listeners, clipboard reads, scripting.executeScript with a dynamic function. Escalates to CRITICAL when a data-collection call is paired with an outbound network send in the same file.
Hidden ElementsDynamically created invisible iframes (display:none, zero dimensions) injected into the DOM — silent affiliate pings or C2 channels. Tracking pixels via new Image().src pointing to external URLs.
Time BombsetTimeout/setInterval with delays ≥ 5 minutes; Date.now() arithmetic gates; localStorage install-date checks that activate behaviour days after first run; Math.random() threshold gates that fire on only a fraction of page loads.
Anti-Analysisnavigator.webdriver checks; zero-width/height window comparisons; bare debugger statements; performance.now() arithmetic used for timing-based sandbox detection.

Severity Levels

  • CRITICAL — Almost certainly malicious; immediate investigation required
  • HIGH — Strongly suspicious; warrants careful review
  • MEDIUM — Potentially risky; review in context
  • LOW — Minor concern; informational
  • INFO — Metadata (hash, file size, etc.)

Installation

Pre-requisite packages

  • Python 3.10+ is required. python3.11, python3.12 or python3.13
  • **python3-venv** - Required if you use virtual environments

Using virtual environments:

sudo apt install python3 python3-venv
git clone https://github.com/ernos/extension-scanner.git
cd extension-scanner

python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

Optional packages

  • **python3-numpy** - Recommended for steganography, system wide installation (otherwise pip install -r requirements.txt)
  • pillow: Recommended for steganography
  • numpy: Recommended for steganography
    ```bash
    pip install pillow numpy
    #System-wide install on ubuntu:
    sudo apt install python3-pillow python3-numpy
git clone https://github.com/ernos/extension-scanner.git
cd extension-scanner
chmod +x extension-scanner.py
mkdir -p ~/.local/share/bin
ln -s $PWD/extension-scanner.py ~/.local/share/bin/extension-scanner


# Required for LSB steganography analysis (optional but recommended)
pip install pillow numpy

# OPTION 1. Only for current user:
# Enable bash completions for simpler use (TAB for autocompleting commands)
mkdir -p ~/.local/share/bash-completion/completions
cp extension-scanner-completions ~/.local/share/bash-completion/completions
echo "source ~/.local/share/bash-completion/completions/extension-scanner-completions" >> ~/.bashrc

# OPTION 2. Enable completions globally for all users (Should be auto-sourced from your .bashrc)
cp extension-scanner-completions /usr/share/bash-completion/completions

If Pillow/NumPy are not installed the tool still runs — LSB and pixel-entropy checks are simply skipped, and a warning is printed.


Usage

usage: xpiscanner [-h] [--update-blocklist] [--min-severity {CRITICAL,HIGH,MEDIUM,LOW,INFO}] [--json] [--compact] [-v] [-m] [--scans CHECK [CHECK ...]]
                  [targets ...]

Firefox Extension Scanner - Scans XPI files for security risks and malware indicators

positional arguments:
  targets               One or more XPI files or directories containing XPIs to analyze

options:
  -h, --help            show this help message and exit
  --update-blocklist, --update, -u
                        Fetch fresh domain blocklists from URLhaus and Peter Lowe's list, merge with the bundled snapshot, and saves to
                        /home/peb/projects/Firefox-Extensions/extension-scanner/blocklist.json. Exits after updating.
  --min-severity {CRITICAL,HIGH,MEDIUM,LOW,INFO}
                        Minimum severity to display (CRITICAL, HIGH, MEDIUM, LOW, INFO; default: INFO)
  --json                Output results as JSON instead of formatted text
  --compact, -c         Print each finding on 1-2 lines instead of the default 3-line format
  -v, --verbose         Enable verbose output: show additional context for findings
  -m, --manifest        Show full extension manifest for each target
  --scans, -s CHECK [CHECK ...]
                        Limit analysis to specific check types. Choices: anti-analysis, api-abuse, credentials, cross-file,
                        file-meta, hidden-elements, obfuscation, payloads, permissions, polyglot, remote-code,
                        signatures, steganography, time-bomb, zip-tricks. Omit to run all checks (default).

    extension-scanner.py — Analyze Firefox (and other browsers) extension XPI files for security risks and malware indicators.
Download Tool