HIGH RISK NaN/100

Better Trading for Firefox

Unknown developer · 11 users at risk

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

Key Security Threats

HIGH Malware Signature

YARA rule match: -postinstall_file_download

/tmp/extract-6eeb33d6efecc723411ca017ab915e6d5ec2d4f928c58039e1bcd247110b218b-3346023319/background.js

HIGH Malware Signature

YARA rule match: -postinstall_system_command

/tmp/extract-6eeb33d6efecc723411ca017ab915e6d5ec2d4f928c58039e1bcd247110b218b-3346023319/background.js

HIGH Malware Signature

YARA rule match: -postinstall_persistence_mechanism

/tmp/extract-6eeb33d6efecc723411ca017ab915e6d5ec2d4f928c58039e1bcd247110b218b-3346023319/background.js

HIGH Code Obfuscation

Obfuscation pattern 'unicode_heavy' detected.

content-scripts/content.js:1

HIGH Malware Signature

YARA rule match: -postinstall_obfuscation

/tmp/extract-6eeb33d6efecc723411ca017ab915e6d5ec2d4f928c58039e1bcd247110b218b-3346023319/content-scripts/content.js

All Findings (112)

View all 112 security findings
Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_persistence_mechanism

Code Obfuscation

Obfuscation pattern 'unicode_heavy' detected.

Malware Signature

YARA rule match: -postinstall_obfuscation

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_persistence_mechanism

Malware Signature

YARA rule match: -NoUseWeakRandom

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_obfuscation

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_system_command

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: e.style

Indicator of Compromise

XIOC detected MD5 Hash: 2f7481c8a8985b1da5624682c6592a5c

Indicator of Compromise

XIOC detected URL: https://developer.mozilla.org/en-US/docs/Web/API/Element/attachShadow#elements_you_can_attach_a_shadow_to

Indicator of Compromise

XIOC detected URL: https://www.pathofexile.com

Indicator of Compromise

XIOC detected URL: https://web.poecdn.com/image/Art/2DItems/Currency/CurrencyRerollRare.png

Indicator of Compromise

XIOC detected URL: https://github.com/wxt-dev/wxt/issues/371

Indicator of Compromise

XIOC detected URL: https://wxt.dev/guide/go-further/testing.html

Indicator of Compromise

XIOC detected URL: https://github.com/appaKappaK/better-trading-for-firefox

Indicator of Compromise

XIOC detected URL: https://poe.ninja/*

Indicator of Compromise

XIOC detected Domain: this.locationwatcher.run

Indicator of Compromise

XIOC detected Domain: h.gq

Indicator of Compromise

XIOC detected Domain: v.goo

Indicator of Compromise

XIOC detected URL: http://addons.mozilla.org/ca/crl.pem0N

Indicator of Compromise

XIOC detected URL: https://poe.ninja/api

Indicator of Compromise

XIOC detected URL: https://www.pathofexile.com

Indicator of Compromise

XIOC detected URL: https://github.com/appaKappaK/better-trading-for-firefox

Indicator of Compromise

XIOC detected Domain: n.bookmarks.folders.at

Indicator of Compromise

XIOC detected Domain: pathofexile.com

Indicator of Compromise

XIOC detected Domain: j.top

Indicator of Compromise

XIOC detected Domain: r.clienty-c.top

Indicator of Compromise

XIOC detected Domain: o.id

Indicator of Compromise

XIOC detected IP: ::8

Indicator of Compromise

XIOC detected Domain: this.id

Indicator of Compromise

XIOC detected Domain: e.watch

Indicator of Compromise

XIOC detected Domain: o.map

Indicator of Compromise

XIOC detected Domain: u.storage

Indicator of Compromise

XIOC detected Domain: c.map

Indicator of Compromise

XIOC detected Domain: browser.storage

Indicator of Compromise

XIOC detected Domain: n.id

Indicator of Compromise

XIOC detected Domain: e.dataset.id

Indicator of Compromise

XIOC detected Domain: t.name

Indicator of Compromise

XIOC detected Domain: i.map

Indicator of Compromise

XIOC detected Domain: it.map

Indicator of Compromise

XIOC detected Domain: c.id

Indicator of Compromise

XIOC detected Domain: n.map

Indicator of Compromise

XIOC detected Domain: r.next

Indicator of Compromise

XIOC detected Domain: dr.call

Indicator of Compromise

XIOC detected Domain: wxt.dev

Indicator of Compromise

XIOC detected Domain: f.call

Indicator of Compromise

XIOC detected Domain: y.is

Indicator of Compromise

XIOC detected Domain: e.data

Indicator of Compromise

XIOC detected Domain: object.prototype.tostring.call

Indicator of Compromise

XIOC detected Domain: t.style.top

Indicator of Compromise

XIOC detected Domain: n.next

Indicator of Compromise

XIOC detected Domain: kn.map

Indicator of Compromise

XIOC detected Domain: e.group

Indicator of Compromise

XIOC detected Domain: t.select

Indicator of Compromise

XIOC detected Domain: r.download

Indicator of Compromise

XIOC detected Domain: r.click

Indicator of Compromise

XIOC detected Domain: developer.mozilla.org

Indicator of Compromise

XIOC detected Domain: web.poecdn.com

Indicator of Compromise

XIOC detected Domain: e.bookmarks.folders.map

Indicator of Compromise

XIOC detected Domain: e.id

Indicator of Compromise

XIOC detected Domain: www.pathofexile.com

Indicator of Compromise

XIOC detected Domain: e.history.entries.map

Indicator of Compromise

XIOC detected Domain: t.id

Indicator of Compromise

XIOC detected Domain: ln.map

Indicator of Compromise

XIOC detected Domain: b.map

Indicator of Compromise

XIOC detected Domain: o.call

Indicator of Compromise

XIOC detected Domain: e.name

Indicator of Compromise

XIOC detected Domain: k.map

Indicator of Compromise

XIOC detected Domain: r.trs.map

Indicator of Compromise

XIOC detected Domain: t.map

Indicator of Compromise

XIOC detected Domain: i.id

Indicator of Compromise

XIOC detected Domain: e.trades.map

Indicator of Compromise

XIOC detected Domain: e.call

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: e.map

Indicator of Compromise

XIOC detected Domain: s.is

Indicator of Compromise

XIOC detected Domain: n.data

Indicator of Compromise

XIOC detected Domain: t.call

Indicator of Compromise

XIOC detected Domain: a.call

Indicator of Compromise

XIOC detected Domain: t3c.mr

Indicator of Compromise

XIOC detected Domain: x.ms

Indicator of Compromise

XIOC detected Domain: poe.ninja

Indicator of Compromise

XIOC detected Domain: globalthis.chrome

Indicator of Compromise

XIOC detected Domain: date.now

Indicator of Compromise

XIOC detected Domain: t.runtime.id

Indicator of Compromise

XIOC detected Domain: github.com

Indicator of Compromise

XIOC detected IP: 9::

Indicator of Compromise

XIOC detected IP: 0::

Indicator of Compromise

XIOC detected IP: 8::b

Indicator of Compromise

XIOC detected Domain: signingca1.addons.mozilla.org

Indicator of Compromise

XIOC detected Domain: mozilla.com

Indicator of Compromise

XIOC detected Domain: content-signature.mozilla.org

Indicator of Compromise

XIOC detected Domain: t337ff0f8c2c6412c77d83b0e7250003f.2f7481c8a8985b1da5624682c6592a5c.addons.mozilla.org

Indicator of Compromise

XIOC detected Domain: a.id

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 4/13/2026 · Version 1.1.0

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.