Malwarebytes Browser Guard
The AI review rates the findings as likely false positive, but the risk score (86/100) still counts them.
Analysis record
- Analysed
- Yesterday
- Version
- v3.3.6
- Artifact
- SHA256 DEC…F7C
- Source
- Findings (non-IoC)
Is Malwarebytes Browser Guard safe?
Malwarebytes Browser Guard blocks ads, trackers, phishing pages and other unwanted content while you browse. It comes from Malwarebytes, a security company, and has about 451,000 users on Firefox. The scan of version 3.3.6 recorded no host permissions and no network endpoints in the manifest data. The only outbound calls the code makes come from content-oap-google.js, the script that handles Google search results, and app/scripts/exclusions/exclusions-mv3.js, which fetches the list of sites you have excluded from filtering.
Four high-severity matches came back under a signature called YARA--mag_php_js, in background.js, content-scripts.js and their two matching .map files. That rule looks for PHP-style web shell patterns. If it were real, it would mean a backdoor had been bundled into the extension's own scripts. The matches land on line 2 of the JavaScript bundles and line 1 of the source maps, which are build leftovers produced by the tools that compile the extension. A signature that trips on both a bundle and its own map is reading the shape of generated code.
Nothing else in the scan supports the idea of a backdoor. There are no suspicious domains, no hidden or encoded payloads, no leaked API keys, and no findings tied to credential access. A compromised build would usually leave more than one vague rule match behind. The scanner tripped on minified, machine-generated JavaScript.
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | mag php js | 4 | background.jscontent-scripts.js.mapcontent-scripts.js +1 more | FP 70% |
Publisher Evidence
Limited evidenceMalwarebytes
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
YARA Rules Matched
1 rule(4 hits)Requested Permissions
19 permissionsExchange messages with programs outside the browser
Access and modify data on every website you visit
Manage, modify, and monitor downloads
Intercept, modify, and block all network requests
Block network requests before they complete
Read data from your clipboard
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality moderate.
Malwarebytes Browser Guard is a content-blocking extension from Malwarebytes, a security vendor with a long public track record, published on the Firefox store with roughly 451,000 users. Version 3.3.6 produced eight findings, four of them high severity. The four high findings are all the same rule, YARA--mag_php_js, matching at content-scripts.js:2, content-scripts.js.map:1, background.js:2 and background.js.map:1. The two medium findings are network hits from app/scripts/exclusions/exclusions-mv3.js and content-oap-google.js. Two manifest-analysis findings are also present but carry no description.
The malware-signature matches deserve a close look because of the severity label, but the shape of the evidence undercuts them. A signature that fires at line 2 of a bundle and line 1 of that bundle's source map is matching a broad pattern across the whole file rather than a specific payload. content-scripts.js and background.js are build outputs, and .js.map files are compiler debug artifacts produced by webpack or esbuild that an attacker has no reason to add. YARA--mag_php_js is a generic PHP/JavaScript web-shell style rule of the sort that trips on packed or encoded text, well below the specificity of a named family signature like a banking trojan or infostealer rule. Nothing else in the scan backs it up. There are no IoC findings, no obfuscation findings, no leaked secrets and no dependency findings. An actual supply-chain compromise dropping a payload into background.js would leave more than one vague rule match, and it would very likely leave at least one endpoint for receiving stolen data.
The two network findings fit the extension's stated job. content-oap-google.js is the content script that handles Google search result pages, the path a content blocker needs to mark or remove ad results, and app/scripts/exclusions/exclusions-mv3.js is the exclusions module, where a blocker fetches the list of sites a user has excluded from filtering. Neither one is a monetized redirect, a tracking collector or a proxy relay. There is no search-hijack behavior in the evidence: no custom search domain, no new-tab replacement, nothing contradicting the "block trackers, ads, phishing" description.
The counterargument is straightforward. A high-severity malware signature is labeled high severity for a reason, and four of them in the core scripts of an extension is not nothing. Someone could fairly argue that Malwarebytes' own bundles should be clean of anything resembling a web shell. That argument would carry more weight if the matches were hits on a narrow family pattern, or if they clustered at one offset in one file. Instead the same rule hits at line 2 of background.js and line 1 of the matching .map, which is what a broad pattern match against generated code looks like. Add a publisher whose entire business is blocking malicious code, and no corroborating signal anywhere in the scan, and the findings read as scanner noise rather than extension behavior.
What would change this: a network finding to a domain that is neither Google nor Malwarebytes-controlled, an obfuscation finding in the same file as the signature, or a YARA match on a named malware family rather than a generic PHP/JS rule.
Key Reasons
- All four high-severity hits are the same generic rule, YARA--mag_php_js, matching at line 1-2 of background.js, content-scripts.js and their .js.map source maps, which are generated build artifacts.
- No corroborating evidence anywhere in the scan: zero IoC, obfuscation, secret, dependency, code-smell or tool-poisoning findings that would accompany a real payload.
- Network findings are limited to content-oap-google.js (Google search result handling) and app/scripts/exclusions/exclusions-mv3.js (the extension's own exclusion list fetch), neither of which is an exfiltration or redirect endpoint.
- Publisher is Malwarebytes, a known security vendor, on the Firefox store with ~451,000 users and a versioned release (3.3.6).
- No browser-hijack signals: no custom search domain, no new-tab replacement, no dynamic URL template construction in the evidence.
False Positive Considerations
- Generic PHP/JavaScript YARA rule (YARA--mag_php_js) matching minified bundle output rather than a named malware family
- Matches extend to .js.map source maps, a hallmark of a file-wide pattern match on machine-generated code
- Zero IoC, obfuscation, secret or dependency findings that normally accompany a real injected payload
- Remaining findings are the extension's own functional network calls (Google search handling, exclusions list)
Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 88%.
Firefox version history
Risk trend by version
8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
VaultysHub extension
Vaultys
Kindredly - A safer, private web for families
Kindredly.ai
VHS - Dev Tools
Vihat Software
Ultimate New Tab Page - AI Search & Dial
Dracon
General Sticker System (GSS)
ElfinL
Patreon Easy Downloader
Cosmious