Firefox Add-ons Verified

Malwarebytes Browser Guard

by Malwarebytes · 451.1K users · 4.2 rating
f368a336-6728-5bff-88e8-4b574afb3b34 | v3.3.6
86/ 100
CRITICAL risk
No change since v3.3.2
Analyst verdict
Do not install

The AI review rates the findings as likely false positive, but the risk score (86/100) still counts them.

Analysis record

Analysed
Yesterday
Version
v3.3.6
Artifact
SHA256 DEC…F7C
Source
Findings (non-IoC)

Is Malwarebytes Browser Guard safe?

Malwarebytes Browser Guard blocks ads, trackers, phishing pages and other unwanted content while you browse. It comes from Malwarebytes, a security company, and has about 451,000 users on Firefox. The scan of version 3.3.6 recorded no host permissions and no network endpoints in the manifest data. The only outbound calls the code makes come from content-oap-google.js, the script that handles Google search results, and app/scripts/exclusions/exclusions-mv3.js, which fetches the list of sites you have excluded from filtering.

Four high-severity matches came back under a signature called YARA--mag_php_js, in background.js, content-scripts.js and their two matching .map files. That rule looks for PHP-style web shell patterns. If it were real, it would mean a backdoor had been bundled into the extension's own scripts. The matches land on line 2 of the JavaScript bundles and line 1 of the source maps, which are build leftovers produced by the tools that compile the extension. A signature that trips on both a bundle and its own map is reading the shape of generated code.

Nothing else in the scan supports the idea of a backdoor. There are no suspicious domains, no hidden or encoded payloads, no leaked API keys, and no findings tied to credential access. A compromised build would usually leave more than one vague rule match behind. The scanner tripped on minified, machine-generated JavaScript.

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

6 detail rows

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHmag php js 4
content-scripts.jsbackground.js.mapbackground.js +1 more
FP 70%

Publisher Evidence

Limited evidence

Malwarebytes

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

Firefox does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.

53
Noisy-finding weight
x1.00
Publisher domain
malwarebytes.com
Observed
Store verification signal
Limited signal
Limited
Extension portfolio
3
Portfolio

13 evidence rows available.

Finding Categories

4
Malware Signatures

YARA Rules Matched

1 rule(4 hits)
mag php js

Requested Permissions

19 permissions
nativeMessaging

Exchange messages with programs outside the browser

Dangerous
http://*/*
Dangerous
https://*/*
Dangerous
<all_urls>

Access and modify data on every website you visit

Dangerous
downloads

Manage, modify, and monitor downloads

High
webRequest

Intercept, modify, and block all network requests

High
webRequestBlocking

Block network requests before they complete

High
clipboardRead

Read data from your clipboard

High
tabs
Medium
activeTab
Medium
alarms
Low
storage
Low
declarativeNetRequest
Low
unlimitedStorage
Low
contextMenus
Low
scripting
Low
https://myaccount.google.com/*
Low
https://www.linkedin.com/*
Low
privacy
Low

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality moderate.

Malwarebytes Browser Guard is a content-blocking extension from Malwarebytes, a security vendor with a long public track record, published on the Firefox store with roughly 451,000 users. Version 3.3.6 produced eight findings, four of them high severity. The four high findings are all the same rule, YARA--mag_php_js, matching at content-scripts.js:2, content-scripts.js.map:1, background.js:2 and background.js.map:1. The two medium findings are network hits from app/scripts/exclusions/exclusions-mv3.js and content-oap-google.js. Two manifest-analysis findings are also present but carry no description.

The malware-signature matches deserve a close look because of the severity label, but the shape of the evidence undercuts them. A signature that fires at line 2 of a bundle and line 1 of that bundle's source map is matching a broad pattern across the whole file rather than a specific payload. content-scripts.js and background.js are build outputs, and .js.map files are compiler debug artifacts produced by webpack or esbuild that an attacker has no reason to add. YARA--mag_php_js is a generic PHP/JavaScript web-shell style rule of the sort that trips on packed or encoded text, well below the specificity of a named family signature like a banking trojan or infostealer rule. Nothing else in the scan backs it up. There are no IoC findings, no obfuscation findings, no leaked secrets and no dependency findings. An actual supply-chain compromise dropping a payload into background.js would leave more than one vague rule match, and it would very likely leave at least one endpoint for receiving stolen data.

The two network findings fit the extension's stated job. content-oap-google.js is the content script that handles Google search result pages, the path a content blocker needs to mark or remove ad results, and app/scripts/exclusions/exclusions-mv3.js is the exclusions module, where a blocker fetches the list of sites a user has excluded from filtering. Neither one is a monetized redirect, a tracking collector or a proxy relay. There is no search-hijack behavior in the evidence: no custom search domain, no new-tab replacement, nothing contradicting the "block trackers, ads, phishing" description.

The counterargument is straightforward. A high-severity malware signature is labeled high severity for a reason, and four of them in the core scripts of an extension is not nothing. Someone could fairly argue that Malwarebytes' own bundles should be clean of anything resembling a web shell. That argument would carry more weight if the matches were hits on a narrow family pattern, or if they clustered at one offset in one file. Instead the same rule hits at line 2 of background.js and line 1 of the matching .map, which is what a broad pattern match against generated code looks like. Add a publisher whose entire business is blocking malicious code, and no corroborating signal anywhere in the scan, and the findings read as scanner noise rather than extension behavior.

What would change this: a network finding to a domain that is neither Google nor Malwarebytes-controlled, an obfuscation finding in the same file as the signature, or a YARA match on a named malware family rather than a generic PHP/JS rule.

Key Reasons

  • All four high-severity hits are the same generic rule, YARA--mag_php_js, matching at line 1-2 of background.js, content-scripts.js and their .js.map source maps, which are generated build artifacts.
  • No corroborating evidence anywhere in the scan: zero IoC, obfuscation, secret, dependency, code-smell or tool-poisoning findings that would accompany a real payload.
  • Network findings are limited to content-oap-google.js (Google search result handling) and app/scripts/exclusions/exclusions-mv3.js (the extension's own exclusion list fetch), neither of which is an exfiltration or redirect endpoint.
  • Publisher is Malwarebytes, a known security vendor, on the Firefox store with ~451,000 users and a versioned release (3.3.6).
  • No browser-hijack signals: no custom search domain, no new-tab replacement, no dynamic URL template construction in the evidence.

False Positive Considerations

  • Generic PHP/JavaScript YARA rule (YARA--mag_php_js) matching minified bundle output rather than a named malware family
  • Matches extend to .js.map source maps, a hallmark of a file-wide pattern match on machine-generated code
  • Zero IoC, obfuscation, secret or dependency findings that normally accompany a real injected payload
  • Remaining findings are the extension's own functional network calls (Google search handling, exclusions list)

Reviewed 2026-10-01; recommended action: suppress false positive; model confidence 88%.

Firefox version history

Risk trend by version

8 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
86
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
3.1.1
Jan 18, 2026
Risk range
60 to 87
Across analyzed versions
Latest analyzed version
3.3.6
Sep 30, 2026
Selected version
critical
Version
v3.3.6
Yesterday
Risk score
86
Findings
8
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Malwarebytes Browser Guard: browse faster, safer, and smarter Tired of ads, scams, and trackers slowing you down? Malwarebytes Browser Guard blocks malicious sites, phishing scams, and creepy trackers—so you can enjoy a faster, cleaner, and safer web. <strong>Why Malwarebytes Browser Guard?</strong> • Block ads and speed up browsing Say goodbye to annoying ads and load pages quicker. • Stop scams before they reach you Automatically blocks phishing, hijackers, and malware sites. • Protect your privacy Keeps trackers from following your every move online. • Simple setup Just install and browse with confidence—no hassle needed. <strong>Key features</strong> • Ad and tracker blocking Remove third-party ads and trackers. • Advanced scam protection Defends against phishing, tech support scams, and hijackers. • CryptoMiner blocker Stops hidden cryptocurrency miners from stealing your CPU. • GDPR cookie consent control Automatically declines cookie pop-ups. Take control of your browsing. Download Malwarebytes Browser Guard today!

Frequently Asked Questions