McAfee has issued a warning on a new Trojan, which hides itself with the same name as a well known firefox extension called “numberedlinks”. The real extension “numberedlinks” adds numbers to links on web pages. The fake extension intercepts passwords and credit card information entered in to the browser and sends it to an external source.
McAfee has labeled the Trojan “FormSpy”. The chances of infection of this virus is relatively small. The virus payload is delivered through email as an exe called the AXM Downloader. Once the attachment is opened the software then connects to the internet and downloads the fake extension. It then injects itself directly into the Firefox user profile and completely bypasses the user confirmation dialog box that normally appears when a user installs an extension.