
A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics, steganography, base64 payloads, zip-tricks, remote-code execution, polyglot tricks, meta data tricks in an attempt to give the analysist information about where deeper analysis is needed.
A command-line tool that analyzes Firefox extension files (.xpi) for signs of malware, obfuscation, hidden payloads, steganography, and other techniques used to sneak malicious code past extension review teams.
extension-scanner.py tears open a Firefox extension and performs a battery of security checks across every file inside it. It then produces a color-coded report with findings ranked by severity.
| Category | What It Looks For |
|---|---|
| Permissions | Dangerous or overly broad permissions (nativeMessaging, <all_urls>, debugger, desktopCapture, etc.) |
| Content Security Policy | unsafe-inline, unsafe-eval, remote script sources in CSP |
| JavaScript Obfuscation | eval(), atob(), Function() constructor abuse, hex escape sequences, split/join/reverse reassembly, encoded string literals, setTimeout with string arguments |
| Suspicious URLs | Hardcoded external domains classified as known-bad (blocklist hit → HIGH), unknown (not on allowlist → MEDIUM), or known-good (allowlisted → suppressed). Run --update-blocklist to refresh the domain blocklist from URLhaus and Peter Lowe's list. |
| Credentials & Secrets | Hardcoded API keys, tokens (AWS, GitHub, Slack, Google), passwords, private keys, and IP addresses |
| Base64 Payloads | Decodes embedded base64 blobs and scans them for executables, scripts, and network code |
| PNG Steganography | Detects data appended after PNG IEND and automatically decodes the trailer (base64, zlib, gzip, and combinations); decoded payloads are recursively scanned for JS obfuscation, credentials, and suspicious URLs. Also detects unknown chunk types, LSB channel anomalies, and unusually high pixel entropy |
| File Metadata | Magic-byte detection of executables (.exe, .elf, .dylib), double extensions (e.g. photo.png.js), suspicious filenames (keylog, miner, wallet) |
| Polyglot Files | Files that are simultaneously valid in two formats (e.g. HTML + ZIP) |
| ZIP Tricks | Path traversal entries, null bytes in filenames, duplicate entries that could fool parsers, payload-carrying ZIP comments |
| Remote Code | Background pages or service workers loaded from remote URLs |
| High Entropy | Files or string literals with suspiciously high entropy (likely encrypted or compressed payloads) |
| API Abuse | Browser extension API calls that indicate data theft or exfiltration: cookies.getAll({}), tabs.query({}), history.search, keyboard listeners, clipboard reads, scripting.executeScript with a dynamic function. Escalates to CRITICAL when a data-collection call is paired with an outbound network send in the same file. |
| Hidden Elements | Dynamically created invisible iframes (display:none, zero dimensions) injected into the DOM — silent affiliate pings or C2 channels. Tracking pixels via new Image().src pointing to external URLs. |
| Time Bomb | setTimeout/setInterval with delays ≥ 5 minutes; Date.now() arithmetic gates; localStorage install-date checks that activate behaviour days after first run; Math.random() threshold gates that fire on only a fraction of page loads. |
| Anti-Analysis | navigator.webdriver checks; zero-width/height window comparisons; bare debugger statements; performance.now() arithmetic used for timing-based sandbox detection. |
CRITICAL — Almost certainly malicious; immediate investigation requiredHIGH — Strongly suspicious; warrants careful reviewMEDIUM — Potentially risky; review in contextLOW — Minor concern; informationalINFO — Metadata (hash, file size, etc.)python3.11, python3.12 or python3.13**python3-venv** - Required if you use virtual environmentsUsing virtual environments:
sudo apt install python3 python3-venv
git clone https://github.com/ernos/extension-scanner.git
cd extension-scanner
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
**python3-numpy** - Recommended for steganography, system wide installation (otherwise pip install -r requirements.txt)git clone https://github.com/ernos/extension-scanner.git
cd extension-scanner
chmod +x extension-scanner.py
mkdir -p ~/.local/share/bin
ln -s $PWD/extension-scanner.py ~/.local/share/bin/extension-scanner
# Required for LSB steganography analysis (optional but recommended)
pip install pillow numpy
# OPTION 1. Only for current user:
# Enable bash completions for simpler use (TAB for autocompleting commands)
mkdir -p ~/.local/share/bash-completion/completions
cp extension-scanner-completions ~/.local/share/bash-completion/completions
echo "source ~/.local/share/bash-completion/completions/extension-scanner-completions" >> ~/.bashrc
# OPTION 2. Enable completions globally for all users (Should be auto-sourced from your .bashrc)
cp extension-scanner-completions /usr/share/bash-completion/completions
If Pillow/NumPy are not installed the tool still runs — LSB and pixel-entropy checks are simply skipped, and a warning is printed.
usage: xpiscanner [-h] [--update-blocklist] [--min-severity {CRITICAL,HIGH,MEDIUM,LOW,INFO}] [--json] [--compact] [-v] [-m] [--scans CHECK [CHECK ...]]
[targets ...]
Firefox Extension Scanner - Scans XPI files for security risks and malware indicators
positional arguments:
targets One or more XPI files or directories containing XPIs to analyze
options:
-h, --help show this help message and exit
--update-blocklist, --update, -u
Fetch fresh domain blocklists from URLhaus and Peter Lowe's list, merge with the bundled snapshot, and saves to
/home/peb/projects/Firefox-Extensions/extension-scanner/blocklist.json. Exits after updating.
--min-severity {CRITICAL,HIGH,MEDIUM,LOW,INFO}
Minimum severity to display (CRITICAL, HIGH, MEDIUM, LOW, INFO; default: INFO)
--json Output results as JSON instead of formatted text
--compact, -c Print each finding on 1-2 lines instead of the default 3-line format
-v, --verbose Enable verbose output: show additional context for findings
-m, --manifest Show full extension manifest for each target
--scans, -s CHECK [CHECK ...]
Limit analysis to specific check types. Choices: anti-analysis, api-abuse, credentials, cross-file,
file-meta, hidden-elements, obfuscation, payloads, permissions, polyglot, remote-code,
signatures, steganography, time-bomb, zip-tricks. Omit to run all checks (default).
extension-scanner.py — Analyze Firefox (and other browsers) extension XPI files for security risks and malware indicators.