
자격 증명 탈취 난독화 전술, 스테가노그래피, base64 페이로드, zip 트릭, 원격 코드 실행, 폴리글롯 트릭, 메타데이터 트릭과 같은 일반적인 멀웨어 트릭을 검사하는 포괄적인 브라우저 확장(.xpi) 멀웨어 스캐너로, 분석가에게 더 깊은 분석이 필요한 위치에 대한 정보를 제공합니다.
Firefox 확장 프로그램 파일(.xpi)을 분석하여 악성 코드, 난독화, 숨겨진 페이로드, 스테가노그래피 등 확장 프로그램 검토 팀을 우회하는 데 사용되는 기술을 탐지하는 명령줄 도구입니다.
extension-scanner.py는 Firefox 확장 프로그램을 열어 내부의 모든 파일에 대해 일련의 보안 검사를 수행합니다. 그런 다음 심각도별로 정렬된 결과를 색상 코드로 구분된 보고서로 생성합니다.
| 카테고리 | 검사 내용 |
|---|---|
| 권한 | 위험하거나 지나치게 광범위한 권한 (nativeMessaging, <all_urls>, debugger, desktopCapture 등) |
| 콘텐츠 보안 정책 | CSP의 unsafe-inline, unsafe-eval, 원격 스크립트 소스 |
| JavaScript 난독화 | eval(), atob(), Function() 생성자 남용, 16진수 이스케이프 시퀀스, split/join/reverse 재조립, 인코딩된 문자열 리터럴, 문자열 인수를 사용하는 setTimeout |
| 의심스러운 URL | 하드코딩된 외부 도메인을 known-bad (블록리스트 적중 → HIGH), unknown (허용 목록에 없음 → MEDIUM), known-good (허용 목록 → 표시 안 함)으로 분류합니다. --update-blocklist를 실행하여 URLhaus 및 Peter Lowe의 목록에서 도메인 블록리스트를 업데이트합니다. |
| 자격 증명 및 비밀 | 하드코딩된 API 키, 토큰 (AWS, GitHub, Slack, Google), 비밀번호, 개인 키, IP 주소 |
| Base64 페이로드 | 포함된 base64 blob을 디코딩하고 실행 파일, 스크립트, 네트워크 코드를 검사합니다 |
| PNG 스테가노그래피 | PNG IEND 뒤에 추가된 데이터를 감지하고 트레일러를 자동으로 디코딩합니다 (base64, zlib, gzip 및 조합); 디코딩된 페이로드는 재귀적으로 JS 난독화, 자격 증명, 의심스러운 URL을 검사합니다. 또한 알 수 없는 청크 유형, LSB 채널 이상, 비정상적으로 높은 픽셀 엔트로피를 감지합니다. |
| 파일 메타데이터 | 실행 파일의 매직 바이트 감지 (.exe, .elf, .dylib), 이중 확장자 (예: photo.png.js), 의심스러운 파일 이름 (keylog, miner, wallet) |
| 폴리글롯 파일 | 두 형식에서 동시에 유효한 파일 (예: HTML + ZIP) |
| ZIP 트릭 | 경로 탐색 항목, 파일 이름의 널 바이트, 파서를 속일 수 있는 중복 항목, 페이로드를 포함한 ZIP 주석 |
| 원격 코드 | 원격 URL에서 로드된 백그라운드 페이지 또는 서비스 워커 |
| 높은 엔트로피 | 의심스러울 정도로 높은 엔트로피를 가진 파일 또는 문자열 리터럴 (암호화되거나 압축된 페이로드) |
| API 남용 | 데이터 도난 또는 유출을 나타내는 브라우저 확장 API 호출: cookies.getAll({}), tabs.query({}), history.search, 키보드 리스너, 클립보드 읽기, 동적 함수를 사용한 scripting.executeScript. 동일 파일에서 데이터 수집 호출과 아웃바운드 네트워크 전송이 함께 나타나면 CRITICAL로 상향합니다. |
| 숨겨진 요소 | DOM에 주입된 동적으로 생성된 보이지 않는 iframe (display:none, 크기 0) — 무음 제휴 핑 또는 C2 채널. 외부 URL을 가리키는 new Image().src를 통한 추적 픽셀 |
| 타임 밤 | 지연 시간 ≥ 5분인 setTimeout/setInterval; Date.now() 산술 게이트; 첫 실행 후 며칠 후에 동작을 활성화하는 localStorage 설치 날짜 확인; 페이지 로드의 일부에서만 실행되는 Math.random() 임계값 게이트 |
| 안티 분석 | navigator.webdriver 확인; 너비/높이가 0인 창 비교; 단독 debugger 문; 타이밍 기반 샌드박스 탐지에 사용되는 performance.now() 산술 |
CRITICAL — 거의 확실히 악성; 즉시 조사 필요HIGH — 강력히 의심됨; 주의 깊은 검토 필요MEDIUM — 잠재적 위험; 문맥에 따라 검토LOW — 경미한 우려; 정보 제공INFO — 메타데이터 (해시, 파일 크기 등)python3.11, python3.12 또는 python3.13**python3-venv** - 가상 환경 사용 시 필요가상 환경 사용:
sudo apt install python3 python3-venv
git clone https://github.com/ernos/extension-scanner.git
cd extension-scanner
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
**python3-numpy** - 스테가노그래피에 권장, 시스템 전체 설치 (그렇지 않으면 pip install -r requirements.txt)git clone https://github.com/ernos/extension-scanner.git
cd extension-scanner
chmod +x extension-scanner.py
mkdir -p ~/.local/share/bin
ln -s $PWD/extension-scanner.py ~/.local/share/bin/extension-scanner
# Required for LSB steganography analysis (optional but recommended)
pip install pillow numpy
# OPTION 1. Only for current user:
# Enable bash completions for simpler use (TAB for autocompleting commands)
mkdir -p ~/.local/share/bash-completion/completions
cp extension-scanner-completions ~/.local/share/bash-completion/completions
echo "source ~/.local/share/bash-completion/completions/extension-scanner-completions" >> ~/.bashrc
# OPTION 2. Enable completions globally for all users (Should be auto-sourced from your .bashrc)
cp extension-scanner-completions /usr/share/bash-completion/completions
Pillow/NumPy가 설치되지 않아도 도구는 계속 실행됩니다 — LSB 및 픽셀 엔트로피 검사는 단순히 건너뛰고 경고가 출력됩니다.
usage: xpiscanner [-h] [--update-blocklist] [--min-severity {CRITICAL,HIGH,MEDIUM,LOW,INFO}] [--json] [--compact] [-v] [-m] [--scans CHECK [CHECK ...]]
[targets ...]
Firefox Extension Scanner - Scans XPI files for security risks and malware indicators
positional arguments:
targets One or more XPI files or directories containing XPIs to analyze
options:
-h, --help show this help message and exit
--update-blocklist, --update, -u
Fetch fresh domain blocklists from URLhaus and Peter Lowe's list, merge with the bundled snapshot, and saves to
/home/peb/projects/Firefox-Extensions/extension-scanner/blocklist.json. Exits after updating.
--min-severity {CRITICAL,HIGH,MEDIUM,LOW,INFO}
Minimum severity to display (CRITICAL, HIGH, MEDIUM, LOW, INFO; default: INFO)
--json Output results as JSON instead of formatted text
--compact, -c Print each finding on 1-2 lines instead of the default 3-line format
-v, --verbose Enable verbose output: show additional context for findings
-m, --manifest Show full extension manifest for each target
--scans, -s CHECK [CHECK ...]
Limit analysis to specific check types. Choices: anti-analysis, api-abuse, credentials, cross-file,
file-meta, hidden-elements, obfuscation, payloads, permissions, polyglot, remote-code,
signatures, steganography, time-bomb, zip-tricks. Omit to run all checks (default).
extension-scanner.py — Analyze Firefox (and other browsers) extension XPI files for security risks and malware indicators.
Read README.md for information on how to interpret findings, limitations, and best practices for use.
This tool is intended for security researchers, analysts, and advanced users who want to perform a
comprehensive static analysis of browser extensions. It should work well for other browsers as well,
but this has only been tested on firefox.
Usage:
python3 extension-scanner.py [OPTIONS] targets...
Targets can be individual .xpi files or directories containing .xpi files. Use glob patterns (e.g. *.xpi) for convenience.